Description
The "Lost Password" reset functionality in ownCloud before 4.0.9 and 4.5.0 does not properly check the security token, which allows remote attackers to change an accounts password via unspecified vectors related to a "Remote Timing Attack."
Remediation
References
Related Vulnerabilities
WordPress Plugin Google Shortlink by BestWebSoft Cross-Site Scripting (1.5.2)
WordPress Plugin Bulk Page Creator Cross-Site Scripting (1.0.9)
WordPress Plugin Simple Events Calendar SQL Injection (1.4.0)
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-4614)
Magento Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2020-9690)