ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were present.
References
Link | Resource |
---|---|
https://owncloud.com/security-advisories/cve-2020-28646/ | Vendor Advisory |
https://owncloud.com/security-advisories/feed/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2021-02-26 15:15
Updated : 2022-09-21 18:18
NVD link : CVE-2020-28646
Mitre link : CVE-2020-28646
CVE.ORG link : CVE-2020-28646
JSON object : View
Products Affected
owncloud
- owncloud_desktop_client
CWE
CWE-427
Uncontrolled Search Path Element