Impact
This vulnerability enables an authenticated user in the Feehi CMS backend who has permission to edit articles to delete any file that is writable by the PHP process. Article image metadata, which may contain user-controlled values, is used directly to build a filesystem path that is passed to unlink() without any validation or sanitization, allowing deletion of arbitrary files beyond the intended image directory. The flaw constitutes a classic directory traversal which can compromise the integrity and confidentiality of the server’s file system.
Affected Systems
The flaw is present in Feehi CMS version 2.1.1. Administrators of websites using this CMS should verify whether they are running this specific release and whether article deletion or editing features are enabled for accounts with write access.
Risk and Exploitability
The vulnerability requires an authenticated backend user, so an attacker must first obtain legitimate user credentials or privilege escalation. Once the edit permission is granted, the attacker can supply crafted image metadata to delete critical files, potentially leading to denial of service or destruction of data. EPSS information is not available, and the flaw is not listed in the CISA KEV catalog. The absence of an exploit probability metric means the risk is uncertain, but the severity of arbitrary file removal warrants prompt action.
OpenCVE Enrichment