Description
ownCloud 4.0.x before 4.0.10 and 4.5.x before 4.5.5 does not properly restrict access to settings.php, which allows remote attackers to edit app configurations of user_webdavauth and user_ldap by editing this file.
Remediation
References
Related Vulnerabilities
Drupal Core 6.x Multiple Cross-Site Scripting Vulnerabilities (6.0)
WordPress Plugin WP-ViperGB Cross-Site Request Forgery (1.3.10)
MySQL CVE-2023-22056 Vulnerability (CVE-2023-22056)
Oracle JRE CVE-2024-21235 Vulnerability (CVE-2024-21235)
WordPress Plugin SH Slideshow 'ajax.php' SQL Injection (3.1.4)