← Back

CVE-2021-26610

nvd nist
Published: Oct 27, 2021Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.

Affected (2)

1 product
Godomall5
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Nhn Commerce
Up to 9
Up to 6
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.