{"cveID":"CVE-2023-49103","vendorProject":"ownCloud","product":"ownCloud graphapi","vulnerabilityName":"ownCloud graphapi Information Disclosure Vulnerability","dateAdded":"2023-11-30","shortDescription":"ownCloud graphapi contains an information disclosure vulnerability that can reveal sensitive data stored in phpinfo() via GetPhpInfo.php, including administrative credentials.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2023-12-21","knownRansomwareCampaignUse":"Unknown","notes":"https://owncloud.com/security-advisories/disclosure-of-sensitive-credentials-and-configuration-in-containerized-deployments/ ;  https://nvd.nist.gov/vuln/detail/CVE-2023-49103","cwes":[],"year":2023,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2023-49103","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"access_ctrl","comments":"This vulnerability is exploited through an unauthenticated information disclosure flaw in the Graph API extension of ownCloud. Attackers first used this vulnerability to gain initial access by targeting the /apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php endpoint, which allowed them to leak sensitive information via the PHP function phpinfo. By modifying the requested URI to bypass Apache web server rewrite rules, attackers could access environment variables containing secrets, such as usernames, passwords, and license keys.","references":["https://arcticwolf.com/resources/blog/cve-2023-49103-cve-2023-49104-and-cve-2023-49105-multiple-critical-vulnerabilities-in-owncloud/","https://www.rapid7.com/blog/post/2023/12/01/etr-cve-2023-49103-critical-information-disclosure-in-owncloud-graph-api/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-49103","technique":"T1005","technique_name_at_mapping":"Data from Local System","mapping_type":"primary_impact","capability_group":"access_ctrl","comments":"This vulnerability is exploited through an unauthenticated information disclosure flaw in the Graph API extension of ownCloud. Attackers first used this vulnerability to gain initial access by targeting the /apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php endpoint, which allowed them to leak sensitive information via the PHP function phpinfo. By modifying the requested URI to bypass Apache web server rewrite rules, attackers could access environment variables containing secrets, such as usernames, passwords, and license keys.","references":["https://arcticwolf.com/resources/blog/cve-2023-49103-cve-2023-49104-and-cve-2023-49105-multiple-critical-vulnerabilities-in-owncloud/","https://www.rapid7.com/blog/post/2023/12/01/etr-cve-2023-49103-critical-information-disclosure-in-owncloud-graph-api/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2023-49103","technique":"T1552","technique_name_at_mapping":"Unsecured Credentials","mapping_type":"primary_impact","capability_group":"access_ctrl","comments":"This vulnerability is exploited through an unauthenticated information disclosure flaw in the Graph API extension of ownCloud. Attackers first used this vulnerability to gain initial access by targeting the /apps/graphapi/vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php endpoint, which allowed them to leak sensitive information via the PHP function phpinfo. By modifying the requested URI to bypass Apache web server rewrite rules, attackers could access environment variables containing secrets, such as usernames, passwords, and license keys.","references":["https://arcticwolf.com/resources/blog/cve-2023-49103-cve-2023-49104-and-cve-2023-49105-multiple-critical-vulnerabilities-in-owncloud/","https://www.rapid7.com/blog/post/2023/12/01/etr-cve-2023-49103-critical-information-disclosure-in-owncloud-graph-api/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1005","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Data from Local System","name_at_mapping":"Data from Local System","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":14,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true},{"id":"T1552","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Unsecured Credentials","name_at_mapping":"Unsecured Credentials","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":13,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}