Description
Session fixation on password protected public links in the ownCloud Server before 10.8.0 allows an attacker to bypass the password protection when they can force a target client to use a controlled cookie.
Remediation
References
Related Vulnerabilities
ownCloud Resource Management Errors Vulnerability (CVE-2015-6500)
Serendipity Other Vulnerability (CVE-2005-3129)
Hustle-Pop-Ups, Slide-ins and Email Opt-ins CSV Injection (6.0.7)
Testimonial Slider Cross-Site Scripting (1.2.1)
WebERP Incorrect Permission Assignment for Critical Resource Vulnerability (CVE-2020-22474)