3.5
CVSSv2

CVE-2015-3011

Published: 08/05/2015 Updated: 03/12/2016
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in the contacts application in ownCloud Server Community Edition prior to 5.0.19, 6.x prior to 6.0.7, and 7.x prior to 7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafted contact.

Vulnerable Product Search on Vulmon Subscribe to Product

owncloud owncloud

debian debian linux 7.0

Vendor Advisories

Multiple vulnerabilities were discovered in ownCloud, a cloud storage web service for files, music, contacts, calendars and many more CVE-2015-3011 Hugh Davenport discovered that the contacts application shipped with ownCloud is vulnerable to multiple stored cross-site scripting attacks This vulnerability is effectively exploitable ...