Loading
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.
Use CWE-352, Owncloud vendor hub and Owncloud product page to widen CVE-2020-28644 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-35946, CVE-2020-28645 and CVE-2020-10252 for nearby disclosures in the same product family.