PT-2026-63330 · Unknown · Page Builder Ck
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Page Builder CK versions prior to 3.6.2
Description
An improper access control issue allows authenticated users to perform an arbitrary file upload, which can lead to Remote Code Execution (RCE), a state where an attacker can execute arbitrary commands on the host machine.
Recommendations
Update Page Builder CK to version 3.6.2 or later.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Page Builder Ck