Impact
The vulnerability is a relative path traversal flaw that allows an attacker with administrative privileges to supply crafted file paths that ownCloud 10 resolves incorrectly arbitrary files. a route to run any code on the server, compromising confidentiality, integrity, and availability of the entire file storage platform. The weakness is formally identified as CWE‑23.
Affected Systems
OwnCloud 10 installations running a version earlier than 10.15.3 are vulnerable. Once the application is upgraded to version 10.15.3 or later, the path‑traversal logic is corrected and the issue is eliminated. The vulnerability does not apply to releases newer than 10.15.3.
Risk and Exploitability
The issue carries a CVSS score of 8.0, indicating high severity. The EPSS score of less than 1 % suggests that exploitation is plausible but rare, and it is not listed in the CISA KEV catalog. Because the exploitation requires administrative privileges, the threat is primarily internal or compromised accounts, but the impact of successful exploitation is substantial, enabling full code execution on the server.
OpenCVE Enrichment