CVE-2011-10004 MEDIUM

CVE-2011-10004: reciply Plugin uploadImage.php unrestricted upload

Vendor N/A
Product reciply Plugin
Weakness CWE-434 · Unrestricted file upload
Published October 16, 2023
Last update September 16, 2024

CVSS base score

6.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

A vulnerability was found in reciply Plugin up to 1.1.7 on WordPress. It has been rated as critical. This issue affects some unknown processing of the file uploadImage.php. The manipulation leads to unrestricted upload. The attack may be initiated remotely. Upgrading to version 1.1.8 is able to address this issue. The identifier of the patch is e3ff616dc08d3aadff9253f1085e13f677d0c676. It is recommended to upgrade the affected component. The identifier VDB-242189 was assigned to this vulnerability.

Key dates

02Disclosure timeline

October 16, 2023 CVE published
September 16, 2024 Record updated

Related vulnerabilities

04Related CVE