CVE-2023-49105: OwnCloud – WebDAV API Authentication Bypass

CVE-2023-49105: OwnCloud - WebDAV API Authentication Bypass-渗透云记 - 专注于网络安全与技术分享
CVE-2023-49105: OwnCloud – WebDAV API Authentication Bypass
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2023-49105: Owncloud – WebDAV API Authentication Bypass

漏洞描述

An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享