CVE-2024-10011

Source
https://cve.org/CVERecord?id=CVE-2024-10011
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10011.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-10011
Published
2024-10-25T07:15:02.637Z
Modified
2026-04-10T05:08:01.757408Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended directory and enables file uploads to directories outside of the web root. Depending on server configuration it may be possible to upload files with double extensions. This vulnerability only affects Windows.

References

Affected packages

Git / github.com/buddypress/buddypress

Affected ranges

Type
GIT
Repo
https://github.com/buddypress/buddypress
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "14.1.0"
        }
    ]
}

Affected versions

14.*
14.1.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10011.json"