CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.8. It may be remotely exploitable. It may lead to a denial-of-service condition.
CVE
CVE-2015-4717
Severity
HIGH
CVSS
7.8
EPSS
2.83%
Original NVD Description
The filename sanitization component in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 does not properly handle $_GET parameters cast by PHP to an array, which allows remote attackers to cause a denial of service (infinite loop and log file consumption) via crafted endpoint file names.