S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-49103 Scanner

CVE-2023-49103 scanner - Information Disclosure vulnerability in owncloud/graphapi

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2023-49103
7.5
CVSScritical
Exploitable remotely over the internet · no authentication required.

An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The graphapi app relies on a third-party GetPhpInfo.php library that provides a URL. When this URL is accessed, it reveals the configuration details of the PHP environment (phpinfo). This information includes all the environment variables of the webserver. In containerized deployments, these environment variables may include sensitive data such as the ownCloud admin password, mail server credentials, and license key. Simply disabling the graphapi app does not eliminate the vulnerability. Additionally, phpinfo exposes various other potentially sensitive configuration details that could be exploited by an attacker to gather information about the system. Therefore, even if ownCloud is not running in a containerized environment, this vulnerability should still be a cause for concern. Note that Docker containers from before February 2023 are not vulnerable to the credential disclosure.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

OwnCloud is a self-hosted file sync and share application that offers services similar to Google Drive and Dropbox. Owncloud/graphapi is a third-party app that enables the integration of ownCloud with Microsoft Graph, a platform that provides access to Office 365 data. This integration allows ownCloud users to access and manage their Office 365 files from within the ownCloud interface.

The CVE-2023-49103 vulnerability was detected in the owncloud/graphapi app. This vulnerability arises from a third-party library called GetPhpInfo.php, which is used by the app. When this library is accessed, it exposes the configuration details of the PHP environment, including all the environment variables of the webserver. In a containerized deployment, such variables may include sensitive data, such as the Owncloud admin password, mail server credentials, and license key. 

When exploited, this vulnerability can result in an attacker gaining access to sensitive data stored on the ownCloud server. Such data may include personal information, business-critical files, and other sensitive data that needs to remain confidential to prevent identity or intellectual property theft. From this perspective, the vulnerability poses a considerable risk to the security of the ownCloud users.

Those who are concerned about the security of their personal and business-critical data can take advantage of the pro features of the s4e.io platform. The platform offers comprehensive security scanning and vulnerability assessment services that can identify and mitigate vulnerabilities in digital assets. By using the platform, users can quickly and easily assess the security of their ownCloud server, ensuring that the vulnerabilities identified in this article and others like it are identified and addressed before they can be exploited.

 

REFERENCES

Solution Advice

To protect against this vulnerability, it is recommended that users:

  • Apply the latest security patches promptly.
  • Remove any third-party apps that have been identified as having security vulnerabilities.
  • Enforce strict network segmentation to contain malware and unauthorized access.
  • Deploy a robust threat detection and response solution to identify and counter threats in real-time.
  • Schedule routine security assessments and audits to ensure that all onsite and offsite systems are secure.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-49103 scanner - Information Disclosure vulnerability in owncloud/graphapi S4E