Loading
ownCloud owncloud/client before 2.7 allows DLL Injection. The desktop client loaded development plugins from certain directories when they were present.
Use CWE-427, Owncloud vendor hub and Owncloud Desktop Client product page to widen CVE-2020-28646 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2016-7102, CVE-2021-44537 and CVE-2015-7298 for nearby disclosures in the same product family.