ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were present.
References
Link | Resource |
---|---|
https://owncloud.com/security-advisories/cve-2020-28646/ | Vendor Advisory |
https://owncloud.com/security-advisories/feed/ | Vendor Advisory |
https://owncloud.com/security-advisories/cve-2020-28646/ | Vendor Advisory |
https://owncloud.com/security-advisories/feed/ | Vendor Advisory |
Configurations
History
21 Nov 2024, 05:23
Type | Values Removed | Values Added |
---|---|---|
References | () https://owncloud.com/security-advisories/cve-2020-28646/ - Vendor Advisory | |
References | () https://owncloud.com/security-advisories/feed/ - Vendor Advisory |
Information
Published : 2021-02-26 15:15
Updated : 2024-11-21 05:23
NVD link : CVE-2020-28646
Mitre link : CVE-2020-28646
CVE.ORG link : CVE-2020-28646
JSON object : View
Products Affected
owncloud
- owncloud_desktop_client
CWE
CWE-427
Uncontrolled Search Path Element