4.3
CVSSv2

CVE-2015-3012

Published: 08/05/2015 Updated: 11/02/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in WebODF prior to 0.5.5, as used in ownCloud, allow remote malicious users to inject arbitrary web script or HTML via a (1) style or (2) font name or (3) javascript or (4) data URI.

Vulnerable Product Search on Vulmon Subscribe to Product

debian debian linux 7.0

kogmbh webodf

Vendor Advisories

Multiple vulnerabilities were discovered in ownCloud, a cloud storage web service for files, music, contacts, calendars and many more CVE-2015-3011 Hugh Davenport discovered that the contacts application shipped with ownCloud is vulnerable to multiple stored cross-site scripting attacks This vulnerability is effectively exploitable ...