Description
OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to /index.php/core/ajax/share.php with a wildcard search parameter to retrieve comprehensive user information.
Problem types
Product status
Credits
Daniel Moreno
References
www.exploit-db.com/exploits/47745 (ExploitDB-47745)
owncloud.org/ (OwnCloud Official Homepage)
ftp.icm.edu.pl/packages/owncloud/ (OwnCloud Software Download Repository)
www.vulncheck.com/advisories/owncloud-username-disclosure (VulnCheck Advisory: OwnCloud 8.1.8 - Username Disclosure)