First published: Mon May 25 2020(Updated: )
A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DEXT5 | <=2.7.1402870 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13442 is classified as a critical remote code execution vulnerability.
To mitigate CVE-2020-13442, upgrade DEXT5 to a version higher than 2.7.1402870 where the vulnerability is patched.
CVE-2020-13442 affects all versions of DEXT5 up to and including 2.7.1402870.
CVE-2020-13442 allows attackers to upload malicious PHP files leading to remote code execution.
CVE-2020-13442 can be exploited by uploading a PHP file through the dext5handler.jsp handler, which is stored in the dext5uploadeddata/ directory.