ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were present.
References
Link | Resource |
---|---|
https://owncloud.com/security-advisories/cve-2020-28646/ | Vendor Advisory |
https://owncloud.com/security-advisories/feed/ | Vendor Advisory |
Configurations
Information
Published : 2021-02-26 07:15
Updated : 2022-09-21 11:18
NVD link : CVE-2020-28646
Mitre link : CVE-2020-28646
JSON object : View
CWE
CWE-427
Uncontrolled Search Path Element
Products Affected
owncloud
- owncloud_desktop_client