First published: Thu May 08 2025(Updated: )
Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
AP Page Builder | <4.0.0 |
The vulnerability has been fixed by the Apollo Theme team in version 4.0.0.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6648 has a high severity level due to its potential for unauthenticated remote exploitation.
To mitigate CVE-2024-6648, upgrade AP Page Builder to version 4.0.0 or later.
CVE-2024-6648 affects all versions of AP Page Builder prior to 4.0.0.
CVE-2024-6648 allows an attacker to exploit absolute path traversal to read arbitrary files on the system.
CVE-2024-6648 can be easily exploited by an unauthenticated remote user due to the nature of the vulnerability.