appagebuilder- PrestaShop module vulnerability (CVE-2024-6648)

Moduleappagebuilder

Score

7.5 High

Date publish

08-05-2025

Versiones afectadas

  • Less than 4.0.0

Description

Absolute Path Traversal vulnerability in AP Page Builder versions prior to 4.0.0 could allow an unauthenticated remote user to modify the 'product_item_path' within the 'config' JSON file, allowing them to read any file on the system.

References

https://www.incibe.es/en/incibe-cert/not...
Third Party Advisory incibe.es

Metrics

cvssMetricV40
sourcecve-coordination@incibe.es
typeSecondary
version4.0
vectorStringCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
baseScore8.7
baseSeverityHIGH
attackVectorNETWORK
attackComplexityLOW
attackRequirementsNONE
privilegesRequiredNONE
userInteractionNONE
vulnConfidentialityImpactHIGH
vulnIntegrityImpactNONE
vulnAvailabilityImpactNONE
subConfidentialityImpactNONE
subIntegrityImpactNONE
subAvailabilityImpactNONE
exploitMaturityNOT_DEFINED
confidentialityRequirementNOT_DEFINED
integrityRequirementNOT_DEFINED
availabilityRequirementNOT_DEFINED
modifiedAttackVectorNOT_DEFINED
modifiedAttackComplexityNOT_DEFINED
modifiedAttackRequirementsNOT_DEFINED
modifiedPrivilegesRequiredNOT_DEFINED
modifiedUserInteractionNOT_DEFINED
modifiedVulnConfidentialityImpactNOT_DEFINED
modifiedVulnIntegrityImpactNOT_DEFINED
modifiedVulnAvailabilityImpactNOT_DEFINED
modifiedSubConfidentialityImpactNOT_DEFINED
modifiedSubIntegrityImpactNOT_DEFINED
modifiedSubAvailabilityImpactNOT_DEFINED
SafetyNOT_DEFINED
AutomatableNOT_DEFINED
RecoveryNOT_DEFINED
valueDensityNOT_DEFINED
vulnerabilityResponseEffortNOT_DEFINED
providerUrgencyNOT_DEFINED
cvssMetricV31
sourcenvd@nist.gov
typePrimary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
baseScore7.5
baseSeverityHIGH
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionNONE
scopeUNCHANGED
confidentialityImpactHIGH
integrityImpactNONE
availabilityImpactNONE
exploitabilityScore3.9
impactScore3.6
Scroll al inicio