CVE-2012-2270: ownCloud

Medium severity, CVSS 5.8. EPSS: 6% chance of exploitation in the next 30 days.

Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.

Affected products

  • ownCloud ownCloud: up to and including 3.0.2
  • ownCloud ownCloud Server: version 3.0.0 only; version 3.0.1 only

Published 2012-04-20. Last modified 2026-06-16.