Security Advisory

CVE-2021-26610

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-10-27 00:45:20
Last updated 2024-08-03 20:26:25
Assigner krcert
State PUBLISHED

Description

The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.