CVE-2020-13894: High severity dext5 vulnerability
Published Jun 7, 2020
·Updated
handler/uploadhandler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field.
Affected Software
1 affected component
DEXT5 DEXT5<=3.5.1402961
Event History
Jun 7, 2020
CVE Published
via MITRE·12:33 AM
Data Sourced
via MITRE·12:33 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-13894?
CVE-2020-13894 is classified as a high-severity vulnerability due to its potential for arbitrary file download leading to data exposure.
2
How do I fix CVE-2020-13894?
To fix CVE-2020-13894, you should update to a version of DEXT5 Editor that is newer than 3.5.1402961 or apply any available security patches.
3
What are the potential impacts of CVE-2020-13894?
The potential impacts of CVE-2020-13894 include unauthorized access to sensitive files on the server, leading to data breaches.
4
Who is affected by CVE-2020-13894?
CVE-2020-13894 affects users of DEXT5 Editor versions up to and including 3.5.1402961.
5
Is there a workaround for CVE-2020-13894?
A potential workaround for CVE-2020-13894 is to restrict access to the upload_handler.jsp file until a patch is applied.