CVE-2024-6552: Booking for Appointments and Events Calendar – Amelia <= 1.2 - Unauthenticated Full Path Disclosure
The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving displayerrors on within test files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6552?
CVE-2024-6552 is classified as a medium severity vulnerability that allows for Full Path Disclosure in the Amelia plugin for WordPress.
How do I fix CVE-2024-6552?
To fix CVE-2024-6552, update the Amelia plugin for WordPress to version 1.2 or later, which resolves the Full Path Disclosure issue.
What causes CVE-2024-6552?
CVE-2024-6552 is caused by the usage of Symfony and leaving display_errors enabled within test files in the Amelia plugin.
Who is affected by CVE-2024-6552?
All users of the Booking for Appointments and Events Calendar – Amelia plugin for WordPress are affected by CVE-2024-6552 if they are using version 1.2 or earlier.
What can attackers do with CVE-2024-6552?
Attackers exploiting CVE-2024-6552 can potentially access sensitive file paths on the server, which may reveal critical information about the application.