CVE-2021-26610

HIGH

godomall5 - Remote Code Execution via Unchecked File Upload

Title source: manual
STIX 2.1

Description

The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0044
EPSS Percentile 36.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-345 CWE-353
Status published
Products (2)
nhn-commerce/godomall5 < 6
nhn-commerce/godomall5 < 9
Published Oct 27, 2021
Tracked Since Feb 18, 2026