Impact
A directory traversal flaw exists in the add‑upload method of the Vendor Image parameter, an attacker can escape the intended upload directory and read or list arbitrary files on the server. The weakness, identified as CWE‑22, provides a remote ability to expose confidential data but does not grant code execution or direct system compromise.
Affected Systems
All current releases of the kirilkirkov Ecommerce‑CodeIgniter‑Bootstrap application are impacted until the repository is updated to the commit de1c9e73ccf3bd032d9a0525c4752290d959dd8b. The project uses a rolling‑release workflow, so formal version numbers are not available; commit prior to the patch.
Risk and Exploitability
With a CVSS score of 5.3 the flaw carries moderate risk, and an EPSS score of less than 1 % indicates a low, yet non‑zero, likelihood of exploitation. The attack can be performed remotely by submitting a crafted request containing a malicious folder value. The vulnerability is not listed in the CISA KEV catalog, but it remains an exploitable path traversal vulnerability for any deployment that has not applied the patch.
OpenCVE Enrichment