Description
The CSRF (Cross Site Request Forgery) token check was improperly implemented on cookie authenticated requests against some ocs API endpoints. This affects ownCloud/core version < 10.6.
Remediation
References
Related Vulnerabilities
SugarCRM CVE-2023-35809 Vulnerability (CVE-2023-35809)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2008-5688)
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5615)
WordPress Plugin WordPress Simple Shopping Cart Cross-Site Request Forgery (3.5)