Description
The contacts application in ownCloud before 4.5.10 and 5.x before 5.0.5 does not properly check the ownership of contacts, which allows remote authenticated users to download arbitrary contacts via unspecified vectors.
Remediation
References
Related Vulnerabilities
WordPress Plugin WordPress Survey & Poll-Quiz, Survey and Poll PHP Object Injection (1.5.5)
Moodle Improper Input Validation Vulnerability (CVE-2014-9060)
MySQL CVE-2019-2632 Vulnerability (CVE-2019-2632)
phpMyAdmin 7PK - Security Features Vulnerability (CVE-2016-5702)
WordPress Plugin wp Dreamwork Gallery 'upload.php' Arbitrary File Upload (2.1)