CVE-2021-26617

HIGH

firstmall - Remote Code Execution via navercheckout_add Function

Title source: llm
STIX 2.1

Description

This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows remote attackers to execute malicious code in Firstmall via navercheckout_add function.

References (1)

Core 1
Core References

Scores

CVSS v3 8.1
EPSS 0.0125
EPSS Percentile 65.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (1)
firstmall/firstmall
Published Feb 25, 2022
Tracked Since Feb 18, 2026