{ "schema_version": "1.4.0", "id": "GHSA-f9w8-q7vq-ch2g", "modified": "2022-05-24T17:18:39Z", "published": "2022-05-24T17:18:39Z", "aliases": [ "CVE-2020-13442" ], "details": "A Remote code execution vulnerability exists in DEXT5Upload in DEXT5 through 2.7.1402870. An attacker can upload a PHP file via dext5handler.jsp handler because the uploaded file is stored under dext5uploadeddata/.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13442" }, { "type": "WEB", "url": "https://github.com/kbgsft/vuln-dext5upload/wiki/File-Upload-to-RCE-in-DEXT5Upload-2.7.1402870-by-xcuter" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2020-05-25T15:15:00Z" } }