CVE-2024-6648
Last modified
CVE-2024-6648 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.
Description
Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apollotheme | Ap Pagebuilder | < 4.0.0 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-6648?
How severe is CVE-2024-6648?
How do I fix CVE-2024-6648?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-6642Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2024-6643Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2024-6644A vulnerability was found in zmops ArgusDBM up to 0.1.0. It …6.3
- CVE-2024-6645A vulnerability was found in WuKongOpenSource Wukong_nocode …6.3
- CVE-2024-6646A vulnerability was found in Netgear WN604 up to 20240710. I…6.9
- CVE-2024-6647** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified a…5.1
- CVE-2024-6649A vulnerability has been found in SourceCodester Employee an…6.5
- CVE-2024-6650A vulnerability was found in SourceCodester Employee and Vis…4.8
- CVE-2024-6651The WordPress File Upload WordPress plugin before 4.24.8 doe…6.1
- CVE-2024-6652A vulnerability was found in itsourcecode Gym Management Sys…8.8
- CVE-2024-6653A vulnerability was found in code-projects Simple Task List …9.8
- CVE-2024-6654Products for macOS enables a user logged on to the system to…6.8
Are you affected by CVE-2024-6648?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
