CVE-2020-13442: DEXT5

Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.

A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.

Affected products

  • DEXT5 DEXT5: up to and including 2.7.1402870

Published 2020-05-25. Last modified 2026-06-17.