A vulnerability (improper input validation) in the DEXT5 Upload solution allows an unauthenticated attacker to download and execute an arbitrary file via AddUploadFile, SetSelectItem, DoOpenFile function.(CVE-2020-7832)
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36231