Impact
ICEcoder versions up to 8.1 contain a logic flaw in the File::check() validation, comparing realpath() against boolean true. This condition never succeeds, allowing attackers who can authenticate to supply traversal sequences or absolute paths. The flaw permits reading, the configured document root, exposing sensitive data and potentially enabling further attacks.
Affected Systems
The vulnerability affects ICEcoder software from ICEcoder:ICEcoder for all releases through version 8.1. No legacy versions are cited as less affected.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPSS score is not available, meaning current exploitation likelihood is unknown. The vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is a remote authenticated session; an attacker must first authenticate to the editor interface before delivering the malicious file parameter.
OpenCVE Enrichment