CVE-2013-2047: ownCloud

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The login page (aka index.php) in ownCloud before 5.0.6 does not disable the autocomplete setting for the password parameter, which makes it easier for physically proximate attackers to guess the password.

Affected products

  • ownCloud ownCloud: up to and including 5.0.5
  • ownCloud ownCloud Server: version 5.0.0 only; version 5.0.1 only; version 5.0.2 only; version 5.0.3 only; version 5.0.4 only

Published 2014-03-14. Last modified 2026-06-16.