Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via arbitrary POST parameters.
| Software | From | Fixed in |
|---|---|---|
| owncloud / owncloud_server | 4.5.0 | 4.5.0.x |
| owncloud / owncloud_server | 4.5.1 | 4.5.1.x |