CVE-2015-3011

low
Published 2015-05-08 · Modified 2026-05-06
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

Multiple cross-site scripting (XSS) vulnerabilities in the contacts application in ownCloud Server Community Edition before 5.0.19, 6.x before 6.0.7, and 7.x before 7.0.5 allow remote authenticated users to inject arbitrary web script or HTML via a crafted contact.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://owncloud.org/security/advisory/?id=oc-sa-2015-001

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.debian.org/security/2015/dsa-3244

OS impact

OSVersionStatusFixed in
debian debian7.0affected

Application impact

VendorProductVersionsFixed
owncloudowncloud{"endIncluding":"5.0.18"}

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.