Path Traversal Vulnerability in BoldThemes Page Builder
CVE-2024-54382
4.9MEDIUM
Key Information:
- Vendor
- Boldthemes
- Status
- Bold Page Builder
- Vendor
- CVE Published:
- 16 December 2024
Summary
The vulnerability CVE-2024-54382 pertains to an improper limitation of a pathname to a restricted directory, also known as a Path Traversal vulnerability, within the BoldThemes Bold Page Builder. This flaw allows unauthorized users to gain access to restricted files in the file system, potentially exposing sensitive information and leading to further exploitation. The vulnerability affects all versions of Bold Page Builder from the initial release up to and including version 5.1.5, emphasizing the urgency for users to update to the latest secure version to mitigate potential risks.
Affected Version(s)
Bold Page Builder <= 5.1.5
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)