ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were present.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://owncloud.com/security-advisories/feed/ | vendor advisory |
https://owncloud.com/security-advisories/cve-2020-28646/ | vendor advisory |