Path Traversal Vulnerability in ICEcoder by ICEcoder Team
CVE-2026-64838
8.7HIGH
What is CVE-2026-64838?
The vulnerability in ICEcoder up to version 8.1 arises from inadequate validation of the oldFileName parameter during file move and rename operations. This flaw permits authenticated users to exploit path traversal sequences, enabling them to relocate files that are writable by the PHP process into the project's web-accessible directory. Consequently, attackers can gain access to sensitive file content, potentially leading to unauthorized disclosures or even file deletions.
Affected Version(s)
ICEcoder 8.0 <= 8.1
