ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2016-1499 - Vulnerability Database

ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2016-1499

High
Reference: CVE-2016-1499
Title: ownCloud Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

ownCloud Server before 8.0.10 8.1.x before 8.1.5 and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a directory listing and possibly cause a denial of service (CPU consumption) via the force parameter to index.php/apps/files/ajax/scan.php.