Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) calendar displayname to part.choosecalendar.rowfields.php or (2) part.choosecalendar.rowfields.shared.php in apps/calendar/templates/; or (3) unspecified vectors to apps/contacts/lib/vcard.php.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2012-09-05T23:00:00Z
Updated: 2024-09-17T00:47:02.104Z
Reserved: 2012-08-21T00:00:00Z
Link: CVE-2012-4397
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2012-09-05T23:55:03.100
Modified: 2012-09-06T16:05:08.253
Link: CVE-2012-4397
Redhat
No data.