Impact
ICEcoder versions up to 8.1 accept an oldFileName parameter during file move and rename operations without proper validation. This flaw allows an authenticated user to supply a path traversal string that points outside the web document root, causing files that the PHP process can write to be moved into the web‑accessible project directory. The attacker can read the relocated file, expose sensitive source code or other confidential data, or delete the original file from its secure location, thereby compromising confidentiality and integrity.
Affected Systems
All ICEcoder releases through version 8.1, distributed by the vendor ICEcoder, are affected. Users should plan a transition to ICEcoder 8.2 or newer where the validation is corrected.
Risk and Exploitability
The CVSS score of 8.7 signals a high severity vulnerability. EPSS information is not available, and the flaw is not listed in the CISA KEV catalog, suggesting limited known exploitation. The attack requires authenticated access to the web interface, so users with privileged roles present the primary threat vector. Once authenticated, an attacker can craft a traversal payload, relocate protected files into the publicly accessible directory, and expose or delete them, impacting confidentiality, integrity, and availability.
OpenCVE Enrichment