Sceawere

Vulnerability Detail

CVE-2026-108567UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

InstantSoft icms2 Path Traversal

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
InstantSoft
Product
icms2
Attack Type
Path Traversal
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in InstantSoft icms2 up to 2.18.2. Impacted is the function files_delete_file of the file system/fields/image.php of the component Image Handler. Performing a manipulation of the argument size results in path traversal. The attack may be initiated remotely. The exploit has been made public and could be used. The patch is named 03d70937f1ff97031523222808726994b8b79379. It is recommended to apply a patch to fix this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T10:16:40.173Z",
  "pubdate": "2026-10-11T10:16:40.173Z",
  "executiveSummary": "A critical path traversal vulnerability exists in the Image Handler component of InstantSoft icms2, affecting versions up to 2.18.2.\nThe vulnerability resides within the files_delete_file function in the file system/fields/image.php script.\nBy manipulating the 'size' argument, an unauthenticated or remote attacker can escape the intended directory structure and delete arbitrary files on the server's filesystem.\nThis flaw presents a severe risk to system integrity and availability, as it allows for unauthorized file deletion, potentially leading to a denial of service or the removal of critical configuration and system files.\nThe attack is remotely exploitable, and public exploit code exists, significantly increasing the risk of active exploitation in the wild.\nSystem administrators are strongly advised to apply the official patch (03d70937f1ff97031523222808726994b8b79379) immediately to mitigate the risk of filesystem compromise.",
  "technicalDetails": "The vulnerability is classified as a Path Traversal (CWE-22) issue within the Image Handler component of InstantSoft icms2. The root cause is the improper validation of user-supplied input provided to the 'size' argument within the files_delete_file function, located in system/fields/image.php.\nIn the affected versions, the application fails to adequately sanitize or restrict the path traversal sequences (such as '../') provided in the 'size' parameter. This parameter is used by the system to locate and remove image-related files. Because the input is processed without sufficient input validation or path canonicalization, the application allows an attacker to break out of the intended base directory.\nThe attack flow proceeds as follows: An attacker sends a crafted request to the web application targeting the vulnerable function. By injecting path traversal characters (e.g., ../../../etc/passwd or other sensitive paths) into the 'size' parameter, the attacker forces the application's underlying filesystem operations to resolve to a target file outside of the legitimate application directory. When the files_delete_file function executes, it performs an unlink or deletion operation on the resolved path.\nThis exploitation technique is highly effective because it relies on the application's internal filesystem interaction logic. The component operates with the privileges of the web server user; therefore, the impact is limited to the scope of what that user account is authorized to delete. However, this is typically sufficient to disrupt the application's functionality, corrupt databases, or delete sensitive configurations, leading to significant system instability.\nBecause the exploit is remotely accessible and public, the barrier to entry for attackers is extremely low. The lack of robust input sanitization and the absence of file path normalization routines are the primary technical failure points. Even if file permissions provide some defense, the ability to delete arbitrary files remains a critical risk factor for any web-based system."
}
CVE-2026-108567: InstantSoft icms2 Path Traversal (MEDIUM Severity, CVSS: 4.3) | Sceawere