CVE-2015-7699
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
26/10/2015
Last modified:
12/04/2025
Description
The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to instantiate arbitrary classes and possibly execute arbitrary code via a crafted mount point option, related to "objectstore."
Impact
Base Score 2.0
9.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:owncloud:owncloud_server:7.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:owncloud:owncloud_server:7.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:owncloud:owncloud_server:7.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:owncloud:owncloud_server:7.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:owncloud:owncloud_server:7.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:owncloud:owncloud_server:7.0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:owncloud:owncloud_server:7.0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:owncloud:owncloud_server:7.0.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:owncloud:owncloud_server:8.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:owncloud:owncloud_server:8.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:owncloud:owncloud_server:8.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:owncloud:owncloud_server:8.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:owncloud:owncloud_server:8.0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:owncloud:owncloud_server:8.1.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



