Path Traversal Vulnerability in BoldThemes Page Builder
CVE-2024-54382

4.9MEDIUM

Key Information:

Vendor
Boldthemes
Status
Bold Page Builder
Vendor
CVE Published:
16 December 2024

Summary

The vulnerability CVE-2024-54382 pertains to an improper limitation of a pathname to a restricted directory, also known as a Path Traversal vulnerability, within the BoldThemes Bold Page Builder. This flaw allows unauthorized users to gain access to restricted files in the file system, potentially exposing sensitive information and leading to further exploitation. The vulnerability affects all versions of Bold Page Builder from the initial release up to and including version 5.1.5, emphasizing the urgency for users to update to the latest secure version to mitigate potential risks.

Affected Version(s)

Bold Page Builder <= 5.1.5

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Trương Hữu Phúc (truonghuuphuc) (Patchstack Alliance)
.