Impact
The weakness, identified as CWE‑79, arises from improper neutralization of user input when pages. embed malicious JavaScript that is stored and later executed in the browsers of any user who views the compromised content.
Affected Systems
Vulnerable versions are ownCloud 10 before 10.15.3 and the embedded DrawIO for ownCloud application before 1.0.2. Organizations running these releases are at risk until the software is updated to the patched versions.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector involves a diagram in the DrawIO app, which stores maliciously crafted input that of any user who views that diagram. With a CVSS score of 8.2 the vulnerability is high severity. The EPSS score is <1%, indicating exploitation likelihood is very low but nonzero. The vulnerability is not listed in the CISA KEV catalog. Furthermore, the description infers that attackers must have access to the DrawIO app, which typically requires authenticated or privileged access within ownCloud.
OpenCVE Enrichment