The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.
CWE-ID: CWE Name: Using the untrusted hierarchy under /srv/wwwroot/htdocs during update as root user could be used to overwrite root files. Source: SUSE
Common Attack Pattern Enumeration and Classification (CAPEC)