Back to search
CVE-2024-6648
Published: May 8, 2025
Modified: May 8, 2025
PUBLISHED
Description
Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.
| Vendor | Product | Versions |
|---|---|---|
Apollo Theme | AP Page Builder | affected 0 - < 4.0.0 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now