Impact
The vulnerability arises in the Vendor Multi-Image Endpoint of the AddProduct.php controller. By manipulating the folder argument, a remote attacker can cause the server to resolve a file path outside the intended directory. This leads to path traversal, a CWE‑22 weakness, that permits reading arbitrary files from the server.
Affected Systems
The affected product is kirilkirkov’s Ecommerce‑CodeIgniter‑Bootstrap framework. No fixed version range is provided because the project follows a rolling release model. Any instance running code before the patch commit 2a9497ff… remains vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 6.9 indicates moderate severity, and the EPSS score of <1% shows a low likelihood of exploitation in the wild. Nonetheless, the exploit is publicly available, and the attack can be performed remotely via crafted HTTP requests. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment