The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.
References
Link | Resource |
---|---|
https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36304 | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2021-10-26 18:15
Updated : 2021-11-01 10:24
NVD link : CVE-2021-26610
Mitre link : CVE-2021-26610
JSON object : View
CWE
CWE-345
Insufficient Verification of Data Authenticity
Products Affected
microsoft
- windows
nhn-commerce
- godomall5