Description

ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endpoint. Because of insufficient validation of the supplied token in showPasswordForm, the server responds differently when an e-mail address corresponds to a valid pending guest user rather than a non-existent user.

INFO

Published Date :

2025-11-05T00:00:00.000Z

Last Modified :

2025-11-05T20:10:32.262Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-59716 vulnerability.

Vendors Products
Owncloud
  • Owncloud
REFERENCES

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact