Record summary

CVE-2024-6648 has a selected CVSS score of 8.7 (high); EIP currently links 1 repository PoC.

Description

Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 23, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 8, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List, VulnCheckBefore 4.0.0affected

Proofs of concept

1

Repository PoCs

GitHubn0d0n/CVE-2024-6648Repository PoCby n0d0nStars: 0Not analyzed2 files

1.8 KiB

GitHub

PoC details

References

2