CVE-2020-7832: RAONWIZ DEXT5 Upload remote code execution vulnerability
Published Sep 7, 2021
·Updated
A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download and execute an arbitrary file via AddUploadFile, SetSelectItem, DoOpenFile function.(CVE-2020-7832)
Affected Software
2 affected components
DEXT5 DEXT5<=5.0.0.117
Microsoft Windows
Event History
Sep 7, 2021
CVE Published
via MITRE·02:47 PM
Data Sourced
via MITRE·02:47 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-7832?
CVE-2020-7832 is considered to have a high severity due to its potential for unauthorized file execution.
2
How do I fix CVE-2020-7832?
To mitigate CVE-2020-7832, ensure that you update to a version of DEXT5 that is higher than 5.0.0.117.
3
What type of attack can exploit CVE-2020-7832?
CVE-2020-7832 can be exploited by unauthenticated attackers to download and execute arbitrary files.
4
Which software is affected by CVE-2020-7832?
CVE-2020-7832 affects the DEXT5 Upload solution, specifically versions up to and including 5.0.0.117.
5
What functions are involved in CVE-2020-7832?
CVE-2020-7832 is related to the AddUploadFile, SetSelectItem, and DoOpenFile functions.