CVE-2025-53827
🟠 Łataj w tym tygodniu
Wykonanie dowolnego kodu w ownCloud z powodu niebezpiecznej metody w Updaterze.
CVSS
9.1
EPSS
0.6%
Exploit
none
Vendor
Opis źródłowy (NVD)
ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous method or function. Attackers with administrative privileges may leverage functionality to execute arbitrary code. This issue has been fixed in version 10.15.3.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.6% |
| Opublikowano (NVD) | 2026-07-06 16:16:26 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-06 22:10:00 UTC |