Access Control Flaw in ownCloud Server
CVE-2020-36251
3.5LOW
What is CVE-2020-36251?
An access control vulnerability exists in ownCloud Server versions before 10.3.0 that allows a non-administrative user with group share access to remove access for all other users in the group. This flaw could result in unauthorized loss of access, affecting collaborative functionality and user data availability.
References
CVSS V3.1
Score:
3.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
