The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: krcert

Published: 2021-10-27T00:45:20

Updated: 2024-08-03T20:26:25.468Z

Reserved: 2021-02-03T00:00:00

Link: CVE-2021-26610

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-10-27T01:15:07.260

Modified: 2021-11-01T17:24:10.893

Link: CVE-2021-26610

cve-icon Redhat

No data.