Description
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.
Remediation
References
Related Vulnerabilities
WordPress Plugin Clean Login Cross-Site Request Forgery (1.7.12)
WordPress Plugin RestroPress-Online Food Ordering System Cross-Site Request Forgery (2.8.2)
WordPress Plugin UnGallery 'search' Parameter Remote Arbitrary Command Execution (2.1.5)
Oracle HTTP Server NULL Pointer Dereference Vulnerability (CVE-2021-34798)