Vulnerability Description
This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows remote attackers to execute malicious code in Firstmall via navercheckout_add function.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Firstmall | Firstmall | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36469Third Party Advisory
- https://www.krcert.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36469Third Party Advisory
FAQ
What is CVE-2021-26617?
CVE-2021-26617 is a vulnerability with a CVSS score of 8.1 (HIGH). This issues due to insufficient verification of the various input values from user’s input. The vulnerability allows remote attackers to execute malicious code in Firstmall via navercheckout_add funct...
How severe is CVE-2021-26617?
CVE-2021-26617 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26617?
Check the references section above for vendor advisories and patch information. Affected products include: Firstmall Firstmall, Microsoft Windows.