Deleting received group share for whole group
Platform: ownCloud Server
– Risk: Low
– CVSS v3 Base Score: 3.5
– CVSS v3 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
– CWE ID: 385
– CWE Name: Improper Privilege Management
A group-share recipient can remove the received group share for all group-recipients.
No data-loss occurs as the share can be re-created again.
– owncloud/core < v10.3.0
Improve permission check when deleting groups.