← Back

CVE-2020-28645

nvd nist
Published: Feb 9, 2021Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

Deleting users with certain names caused system files to be deleted. Risk is higher for systems which allow users to register themselves and have the data directory in the web root. This affects ownCloud/core versions < 10.6.

Affected (1)

Products: Owncloud: Owncloud
1 product
Owncloud
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 10.6.0

Timeline

No history available yet.