
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2019-25337 is a username enumeration vulnerability in OwnCloud 8.1.8 that allows unauthenticated remote attackers to discover valid user accounts by sending crafted GET requests to the /index.php/core/ajax/share.php endpoint. The vulnerability was published on February 12, 2026, and affects OwnCloud version 8.1.8 specifically. It is classified as CWE-203 (Observable Discrepancy). The CVSS v3.1 base score is 9.8 (Critical), though the more contextually accurate CVSS v4.0 score is 5.3 (Medium), reflecting the limited direct impact of information disclosure (Feedly).
The root cause is an observable discrepancy (CWE-203) in the OwnCloud share functionality, where the /index.php/core/ajax/share.php endpoint returns different responses depending on whether a queried username exists. An attacker can send crafted GET requests with wildcard search parameters to this endpoint without any authentication, and the differing server responses reveal which usernames are valid within the OwnCloud instance. No special privileges or user interaction are required to exploit this flaw. A technical write-up describing the exploitation mechanics is available at infinitsec.net (Feedly, InfinitSec).
Successful exploitation allows an unauthenticated remote attacker to enumerate valid usernames within an OwnCloud 8.1.8 instance, exposing user account information that can be leveraged for follow-on attacks such as credential brute-forcing, password spraying, or targeted social engineering campaigns. While the direct impact is limited to confidentiality of account metadata, the reconnaissance capability it provides can significantly lower the barrier for more severe attacks against the affected system and its users (Feedly).
There is no public proof-of-concept exploit code known at this time, and no evidence of active in-the-wild exploitation has been observed. The EPSS score is approximately 0.00126 (0.126%), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).
/index.php/core/ajax/share.php with a wildcard or partial username as the search parameter (e.g., ?search=* or ?search=a)./index.php/core/ajax/share.php from a single IP or small range of IPs, especially with wildcard or sequential search parameters.search parameter values in rapid succession from unauthenticated sources.No official patch has been confirmed for OwnCloud 8.1.8 at this time. Recommended mitigations include: (1) restricting access to the /index.php/core/ajax/share.php endpoint via firewall rules or a web application firewall (WAF) to allow only authenticated or trusted traffic; (2) implementing rate limiting on the share.php endpoint to prevent automated enumeration; (3) reviewing access logs for suspicious enumeration patterns; and (4) upgrading to a newer, supported version of OwnCloud or its successor Nextcloud if feasible, as OwnCloud 8.1.8 is an end-of-life release (Feedly).
Coverage of CVE-2019-25337 has been limited to automated vulnerability tracking platforms and a single technical blog post. The cybersecurity community has not produced notable commentary or vendor statements beyond the initial disclosure. The vulnerability was highlighted in a roundup of new CVEs with high CVSS scores published on cyberhub.blog (CyberHub Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."