Description
The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.
Published: 2021-10-27
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-13404 The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.
History

No history.

Subscriptions

Microsoft Windows
Nhn-commerce Godomall5
cve-icon MITRE

Status: PUBLISHED

Assigner: krcert

Published:

Updated: 2024-08-03T20:26:25.468Z

Reserved: 2021-02-03T00:00:00.000Z

Link: CVE-2021-26610

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-10-27T01:15:07.260

Modified: 2024-11-21T05:56:35.000

Link: CVE-2021-26610

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses