CVE-2017-9338: ownCloud
Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.
Inadequate escaping lead to XSS vulnerability in the search module in ownCloud Server before 8.2.12, 9.0.x before 9.0.10, 9.1.x before 9.1.6, and 10.0.x before 10.0.2. To be exploitable a user has to write or paste malicious content into the search dialogue.
Affected products
- ownCloud ownCloud: before 8.2.12 (fixed in 8.2.12); from 9.0.0, before 9.0.10 (fixed in 9.0.10); from 9.1.0, before 9.1.6 (fixed in 9.1.6); from 10.0.0, before 10.0.2 (fixed in 10.0.2)
Published 2017-07-17. Last modified 2026-06-17.