Impact
The vulnerability resides in the files_delete_file function of the Image Handler in InstantSoft icms2. A malformed *size* parameter can trigger a path traversal that allows an attacker to delete or otherwise manipulate arbitrary files on the server. This could result in defacement, data loss, or further exploitation. The issue carries a CVSS score of 5.3 and the exploit is publicly available, indicating a moderate but real threat.
Affected Systems
InstantSoft icms2 versions up to and including 2.18.2 are affected. The flaw is located in the file system/fields/image.php component. Administrators should verify whether their deployment runs a version <= 2.18.2 and assess the impact on file handling and upload services.
Risk and Exploitability
The CVSS base score of 5.3 classifies the risk as moderate. Although the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the public exploit demonstrates that remote attackers can trigger the traversal by sending a crafted request to the image.php endpoint. Once the attacker gains the ability to delete files, they could cause denial‑of‑service or prepare for further compromise. Prompt remediation is recommended.
OpenCVE Enrichment