CVE-2020-13894: DEXT5

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field.

Affected products

  • DEXT5 DEXT5: up to and including 3.5.1402961

Published 2020-06-07. Last modified 2026-06-17.