ZeroHour

CVE-2021-26610

CVSS 3.1
8.8 high
EPSS
<1%p38
Published
()
Modified
Description

The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.

Vendors
nhn-commerce
Products
godomall5
Weakness
CWE-353, CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.