AP Page Builder Absolute Path Traversal Vulnerability

Vulnerability

A path traversal vulnerability has been identified in AP Page Builder versions prior to 4.0.0. This vulnerability allows an unauthenticated remote user to manipulate the 'product_item_path' within the 'config' JSON file, potentially leading to unauthorized access to any file on the system.

Impact

Exploitation of this vulnerability could result in unauthorized file access on the server.

Remediation

Users can upgrade to AP Page Builder version 4.0.0 or later to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
3.3
exploitability
7.6
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.