CVE-2023-49103 is an information-disclosure vulnerability in ownCloud graphapi versions 0.2.x before 0.2.1 and 0.3.x before 0.3.1. The application includes a third-party GetPhpInfo.php component that exposes a URL serving PHP phpinfo() output. The output discloses PHP and web-server configuration, including web-server environment variables. In containerized deployments, these variables can contain ownCloud administrator credentials, mail-server credentials, and license keys. Disabling graphapi alone does not remove the exposed component or eliminate the vulnerability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides a proof-of-concept (PoC) environment for CVE-2023-49103, a vulnerability in ownCloud. The structure consists of a Dockerfile that builds an Apache HTTP server with both HTTP and HTTPS enabled, using custom configuration files and SSL certificates. The payload directory contains a full ownCloud web application, including HTML, CSS, and JavaScript assets, mimicking a real ownCloud deployment. The Docker container exposes ports 80 (HTTP) and 443 (HTTPS), allowing users to interact with the vulnerable ownCloud instance for testing or exploitation purposes. No active exploit code is included; instead, this repository is intended to facilitate vulnerability research and demonstration by providing a ready-to-use vulnerable environment. Notable endpoints include the web server root (http://localhost:80/ and https://localhost:443/) and the Apache configuration files. The repository is well-structured for PoC and research use, but does not contain weaponized or automated exploitation scripts.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An information disclosure vulnerability in ownCloud's graphapi, potentially exposing sensitive information.
Unauthenticated information disclosure in ownCloud graphapi exposing sensitive credentials/configuration (notably in containerized deployments).
A critical ownCloud vulnerability that can disclose sensitive credentials and configuration data, including PHP environment configuration and, in containerized deployments, admin passwords, mail server credentials, and license keys.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.