Description
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying restore privileges when restoring a file. The restore capability of Nextcloud/ownCloud was not verifying whether a user has only read-only access to a share. Thus a user with read-only access was able to restore old versions.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2012-1737 Vulnerability (CVE-2012-1737)
WordPress Plugin Catchers Helpdesk and Ticket system for Support Cross-Site Scripting (2.6.7)
Oracle JRE CVE-2013-5838 Vulnerability (CVE-2013-5838)
WordPress Plugin Jigoshop Multiple Unspecified Vulnerabilities (1.17.13)
OpenSSL Permissions, Privileges, and Access Controls Vulnerability (CVE-2010-1633)