CVE-2020-13894: DEXT5
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field.
Affected products
- DEXT5 DEXT5: up to and including 3.5.1402961
Published 2020-06-07. Last modified 2026-06-17.