CVE-2013-2044: ownCloud
Medium severity, CVSS 5.8. EPSS: 1.6% chance of exploitation in the next 30 days.
Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.
Affected products
- ownCloud ownCloud: up to and including 5.0.5
- ownCloud ownCloud Server: version 5.0.0 only; version 5.0.1 only; version 5.0.2 only; version 5.0.3 only; version 5.0.4 only
Published 2014-03-14. Last modified 2026-06-16.