CVE-2026-14635 Details
Description
A security flaw has been discovered in kirilkirkov Ecommerce-CodeIgniter-Bootstrap up to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. This issue affects some unknown processing of the file application/modules/vendor/controllers/AddProduct.php of the component Vendor Multi-Image Endpoint. Performing a manipulation of the argument folder results in path traversal. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The patch is named 2a9497ff11f36e573ad99e1c357ff0e6ded49745. Applying a patch is the recommended action to fix this issue.
A path traversal vulnerability has been identified in KirilKirkov Ecommerce-CodeIgniter-Bootstrap versions prior to 222ff31c06687b1c6d0e1ab63953f82c3674c52b. The issue arises in the file 'application/modules/vendor/controllers/AddProduct.php', specifically within the Vendor Multi-Image Endpoint. The vulnerability allows for manipulation of the 'folder' argument, leading to unauthorized access to the file system. This issue can be exploited remotely, with the published exploit available for use.
Users are advised to update to version 2a9497f, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 4, 2026CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/ | [email protected] | Source CodeVendor |
| https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/commit/2a9497ff11f36e573ad99e1c357ff0e6ded49745 | [email protected] | Source CodeVendor |
| https://github.com/kirilkirkov/Ecommerce-CodeIgniter-Bootstrap/security/advisories/GHSA-6whv-r5hm-vcjr | [email protected] | AdvisoryExploitRemedyVendor |
| https://vuldb.com/cve/CVE-2026-14635 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/845906 | [email protected] | Permission Required |
| https://vuldb.com/vuln/376150 | [email protected] | Permission Required |
| https://vuldb.com/vuln/376150/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kirilkirkov Ecommerce-CodeIgniter-Bootstrap | <= 222ff31c06687b1c6d0e1ab63953f82c3674c52b |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 4, 2026 | New CVE Received | [email protected] |
Volerion