CVE-2020-13894

Publication date

2020-06-07 00:33:54

Family

mitre

State

PUBLISHED

Description

handler/upload_handler.jsp in DEXT5 Editor through 3.5.1402961 allows an attacker to download arbitrary files via the savefilepath field.