CVE-2019-25337

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
12/02/2026
Last modified:
13/02/2026

Description

OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to /index.php/core/ajax/share.php with a wildcard search parameter to retrieve comprehensive user information.