Loading
An issue was discovered in ownCloud owncloud/core before 10.13.1. An attacker can access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. This occurs because pre-signed URLs can be accepted even when no signing-key is configured for the owner of the files. The earliest affected version is 10.6.0.
Use CWE-287, Owncloud vendor hub and Owncloud Server product page to widen CVE-2023-49105 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2014-2052, CVE-2016-1499 and CVE-2020-36252 for nearby disclosures in the same product family.