Loading
The public share controller in the ownCloud server before version 10.8.0 allows a remote attacker to see the internal path and the username of a public share by including invalid characters in the URL.
Use CWE-209, Owncloud vendor hub and Owncloud product page to widen CVE-2021-35947 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-35946, CVE-2020-28645 and CVE-2020-10252 for nearby disclosures in the same product family.