216.73.217.22

CVE-2011-10013

· Published 13/08/2025 21:15 · Modified 13/08/2025 21:15

Labels: CVE-2011-10013 2025-08-13CVE-2011-10013CWE-94[email protected]

Essential information

Published
13/08/2025 21:15
Modified
13/08/2025 21:15
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Traq versions 2.0 through 2.3 contain a remote code execution vulnerability in the admincp/common.php script. The flawed authorization logic fails to halt execution after a failed access check, allowing unauthenticated users to reach admin-only functionality. This can be exploited via plugins.php to inject and execute arbitrary PHP code.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
traq / traq cpe:2.3:a:traq:traq:2.0-2.3:*:*:*:*:*:*:*

References