CVE-2020-13442: Malicious File Upload
Published May 25, 2020
·Updated
A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.
Affected Software
1 affected component
DEXT5 DEXT5<=2.7.1402870
Event History
May 25, 2020
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-13442?
CVE-2020-13442 is classified as a critical remote code execution vulnerability.
2
How do I fix CVE-2020-13442?
To mitigate CVE-2020-13442, upgrade DEXT5 to a version higher than 2.7.1402870 where the vulnerability is patched.
3
What systems are affected by CVE-2020-13442?
CVE-2020-13442 affects all versions of DEXT5 up to and including 2.7.1402870.
4
What type of attack does CVE-2020-13442 allow?
CVE-2020-13442 allows attackers to upload malicious PHP files leading to remote code execution.
5
How is CVE-2020-13442 exploited?
CVE-2020-13442 can be exploited by uploading a PHP file through the dext5handler.jsp handler, which is stored in the dext5uploadeddata/ directory.