CVE-2020-7875

HIGH

DEXT5 Upload <5.0.0.117 - Code Injection

Title source: llm
STIX 2.1

Description

DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution.

Scores

CVSS v3 7.5
EPSS 0.0041
EPSS Percentile 61.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-494
Status published
Products (1)
dext5/dext5upload < 5.0.0.117
Published Oct 28, 2021
Tracked Since Feb 18, 2026