CVE-2020-13442: DEXT5
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.
Affected products
- DEXT5 DEXT5: up to and including 2.7.1402870
Published 2020-05-25. Last modified 2026-06-17.