A cross-site scripting (XSS) vulnerability in all ownCloud versions prior to 5.0.5 including the 4.0.x branch allows remote attackers to execute arbitrary javascript when a user opens a special crafted URL.
This vulnerability exists in the bundled 3rdparty plugin “jPlayer”, “jPlayer” released version 2.2.20 which addresses the problem.
It is recommended that all instances are upgraded to ownCloud Server 5.0.4, 4.5.9 or 4.0.14.
The ownCloud team thanks the following people for their research and responsible disclosure of the above advisory: