Session Fixation Vulnerability in ownCloud Server
CVE-2021-35948
5.4MEDIUM
What is CVE-2021-35948?
A session fixation vulnerability exists in ownCloud Server versions prior to 10.8.0. This flaw allows attackers to bypass password protection on public links by forcing a targeted user to use a cookie they control. By exploiting this vulnerability, an attacker could gain unauthorized access to sensitive data, undermining the security measures designed to protect user sessions.
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
