Vulnerability Description
A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dext5 | Dext5 | <= 2.7.1402870 |
Related Weaknesses (CWE)
References
- https://github.com/kbgsft/vuln-dext5upload/wiki/File-Upload-to-RCE-in-DEXT5UploaExploitThird Party Advisory
- https://github.com/kbgsft/vuln-dext5upload/wiki/File-Upload-to-RCE-in-DEXT5UploaExploitThird Party Advisory
FAQ
What is CVE-2020-13442?
CVE-2020-13442 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5...
How severe is CVE-2020-13442?
CVE-2020-13442 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-13442?
Check the references section above for vendor advisories and patch information. Affected products include: Dext5 Dext5.