Description
ownCloud 10.7 has an incorrect access control vulnerability, leading to remote information disclosure. Due to a bug in the related API endpoint, the attacker can enumerate all users in a single request by entering three whitespaces. Secondary, the retrieval of all users on a large instance could cause higher than average load on the instance.
Remediation
References
Related Vulnerabilities
WordPress Plugin Brizy-Page Builder Arbitrary File Upload (2.4.44)
WordPress Plugin Simple Download Monitor Cross-Site Scripting (3.5.3)
Oracle Database Server CVE-2011-2253 Vulnerability (CVE-2011-2253)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-1836)
Oracle Database Server CVE-2008-1814 Vulnerability (CVE-2008-1814)