Impact
ICEcoder 8.1 is vulnerable to unauthenticated remote code execution through the terminal-xhr.php endpoint. The flaw combines an authentication bypass (by sending a password parameter), a CSRF validation bypass (using a non‑empty csrf parameter), and unsanitized command execution via PHP's proc_open(). An attacker can craft a single POST request that is executed as the web‑server user, allowing arbitrary OS command execution. This is a high‑severity weakness identified as CWE‑306.
Affected Systems
The vulnerability affects ICEcoder version 8.1. This version is hosted under the ICEcoder product line and is used by developers to edit code in a web interface.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as a high‑impact vulnerability. No EPSS score is available, and the vulnerability is not currently listed in the CISA KEV catalog. Attackers can exploit the flaw remotely over HTTP, requiring no prior authentication or authorization, making it easily exploitable in a publicly accessible environment.
OpenCVE Enrichment