Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by the Apollo Theme team in version 4.0.0.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54461 | Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system. |
Tue, 15 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 13 May 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apollotheme
Apollotheme ap Pagebuilder |
|
| CPEs | cpe:2.3:a:apollotheme:ap_pagebuilder:*:*:*:*:*:prestashop:*:* | |
| Vendors & Products |
Apollotheme
Apollotheme ap Pagebuilder |
|
| Metrics |
cvssV3_1
|
Thu, 08 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 May 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system. | |
| Title | Path Traversal in AP Page Builder | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-05-08T13:11:48.054Z
Reserved: 2024-07-10T12:20:26.489Z
Link: CVE-2024-6648
Updated: 2025-05-08T13:11:24.685Z
Status : Analyzed
Published: 2025-05-08T13:15:50.657
Modified: 2025-05-13T18:28:07.253
Link: CVE-2024-6648
No data.
OpenCVE Enrichment
No data.
EUVD