CVE-2023-23948

The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable to SQL injection in `FileContentProvider.kt`. This issue can lead to information disclosure. Two databases, `filelist` and `owncloud_database`, are affected. In version 3.0, the `filelist` database was deprecated. However, injections affecting `owncloud_database` remain relevant as of version 3.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:owncloud:owncloud_client:*:*:*:*:*:android:*:*

History

26 Mar 2025, 17:06

Type Values Removed Values Added
First Time Owncloud owncloud Client
CPE cpe:2.3:a:owncloud:owncloud:*:*:*:*:*:android:*:* cpe:2.3:a:owncloud:owncloud_client:*:*:*:*:*:android:*:*

21 Nov 2024, 07:47

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 6.2
References () https://securitylab.github.com/advisories/GHSL-2022-059_GHSL-2022-060_Owncloud_Android_app/ - Exploit, Third Party Advisory () https://securitylab.github.com/advisories/GHSL-2022-059_GHSL-2022-060_Owncloud_Android_app/ - Exploit, Third Party Advisory
Summary
  • (es) La aplicación ownCloud para Android permite a los usuarios de ownCloud acceder, compartir y editar archivos y carpetas. La versión 2.21.1 de la aplicación ownCloud para Android es vulnerable a la inyección SQL en `FileContentProvider.kt`. Este problema puede dar lugar a la divulgación de información. Dos bases de datos, `filelist` y `owncloud_database`, se ven afectadas. En la versión 3.0, la base de datos `filelist` quedó obsoleta. Sin embargo, las inyecciones que afectan a `owncloud_database` siguen siendo relevantes a partir de la versión 3.0.
Summary (en) The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable to SQL injection in `FileContentProvider.kt`. This issue can lead to information disclosure. Two databases, `filelist` and `owncloud_database`, are affected. In version 3.0, the `filelist` database was deprecated. However, injections affecting `owncloud_database` remain relevant as of version 3.0. (en) The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable to SQL injection in `FileContentProvider.kt`. This issue can lead to information disclosure. Two databases, `filelist` and `owncloud_database`, are affected. In version 3.0, the `filelist` database was deprecated. However, injections affecting `owncloud_database` remain relevant as of version 3.0.

Information

Published : 2023-02-13 17:15

Updated : 2025-03-26 17:06


NVD link : CVE-2023-23948

Mitre link : CVE-2023-23948

CVE.ORG link : CVE-2023-23948


JSON object : View

Products Affected

owncloud

  • owncloud_client
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')