CVE-2019-25337
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
12/02/2026
Last modified:
13/02/2026
Description
OwnCloud 8.1.8 contains a username enumeration vulnerability that allows remote attackers to discover user accounts by manipulating the share.php endpoint. Attackers can send crafted GET requests to /index.php/core/ajax/share.php with a wildcard search parameter to retrieve comprehensive user information.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
9.80
Severity 3.x
CRITICAL



