Security Advisory
CVE-2021-26610
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.