CVE-2024-49649: WordPress Build App Online plugin <= 1.0.23 - Local File Inclusion vulnerability
Published Jan 7, 2025
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in hakeemnala Build App Online build-app-online allows PHP Local File Inclusion.This issue affects Build App Online: from n/a through <= 1.0.23.
Affected Software
3 affected components
Abdul Hakeem Build App Online<=1.0.23
WordPress Build App Online plugin<=1.0.23
Buildapp Build App Online Wordpress<=1.0.23
Event History
Jan 7, 2025
CVE Published
via MITRE·10:49 AM
Data Sourced
via MITRE·10:49 AM
DescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-49649?
CVE-2024-49649 has a high severity level due to its potential for PHP Local File Inclusion exploits.
2
How do I fix CVE-2024-49649?
To fix CVE-2024-49649, upgrade Build App Online to version 1.0.24 or later.
3
Which versions of Build App Online are affected by CVE-2024-49649?
CVE-2024-49649 affects all versions of Build App Online up to and including 1.0.23.
4
Can CVE-2024-49649 be exploited remotely?
Yes, CVE-2024-49649 can be exploited remotely, allowing attackers to execute arbitrary local files.
5
Is there a workaround for CVE-2024-49649?
A temporary workaround for CVE-2024-49649 is to restrict access to the affected PHP files until an upgrade can be performed.