CVE-2021-26610

HIGH

godomall5 - Remote Code Execution via Unchecked File Upload

Title source: manual
STIX 2.1

Description

The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0044
EPSS Percentile 34.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-353 CWE-345
Status published
Products (2)
nhn-commerce/godomall5 < 6
nhn-commerce/godomall5 < 9
Published Oct 27, 2021
Tracked Since Feb 18, 2026