CVE-2020-13894

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/06/2020
Last modified:
11/06/2020

Description

handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dext5:dext5:*:*:*:*:*:*:*:* 3.5.1402961 (including)