Description
Multiple cross-site scripting (XSS) vulnerabilities in the (1) Gallery and (2) core components in ownCloud Server before 5.016 and 6.0.x before 6.0.3 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to the print_unescaped function.
Remediation
References
Related Vulnerabilities
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9853)
WordPress Plugin Tweet Blender Cross-Site Scripting (4.0.1)
WordPress 3.8.x Multiple Vulnerabilities (3.8 - 3.8.17)
IBM RTC Improper Restriction of XML External Entity Reference Vulnerability (CVE-2021-20502)