CVE-2012-4391
Cross-site request forgery (CSRF) vulnerability in core/ajax/appconfig.php in ownCloud before 4.0.7 allows remote attackers to hijack the authentication of administrators for requests that edit the app configurations.
Date published : 2012-09-05
http://owncloud.org/changelog/
https://github.com/owncloud/core/commit/5192eecce239a0b7ade1e60a6cf03075e5cfc188
