CVE-2021-26610

Publication date

2021-10-27 00:45:20

Family

krcert

State

PUBLISHED

Description

The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.