#VU25682 Improper access control in ownCloud Server
Published: February 28, 2020
ownCloud Server
ownCloud
Description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote attacker who knows the public-link hash and the original filename of the image can bypass implemented security restrictions and gain unauthorized access to the preview-image of a password-protected public-link.