The move_uploaded_file function in godomall5 does not...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 30, 2023
Description
Published by the National Vulnerability Database
Oct 27, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Jan 30, 2023
The move_uploaded_file function in godomall5 does not perform an integrity check of extension or authority when user upload file. This vulnerability allows an attacker to execute an remote arbitrary code.
References