← Back to browse · API

CVE-2011-10011

Severity
CRITICAL
CVSS
10.0
EPSS
0.01704
Risk score
40.6
CISA KEV
No
PoC
No
Published
2025-08-13
Modified
2026-05-15
First seen
2026-08-07
Aliases
EUVD-2011-5238, GHSA-9RC9-J8HF-3W5M
Products
WeBid:WeBid 0 ≤1.0.2
Sources
euvd EUVD-2011-5238

Description

WeBid 1.0.2 contains a remote code injection vulnerability in the converter.php script, where unsanitized input in the to parameter of a POST request is written directly into includes/currencies.php. This allows unauthenticated attackers to inject arbitrary PHP code, resulting in persistent remote code execution when the modified script is accessed or included by the application.

References