Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7jgq-pvpg-hqwq

Опубликовано: 14 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 7.5

Описание

CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal sequences to write files outside the intended template directory.

CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal sequences to write files outside the intended template directory.

EPSS

Процентиль: 36%
0.00149
Низкий

5.3 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
26 дней назад

CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal sequences to write files outside the intended template directory.

EPSS

Процентиль: 36%
0.00149
Низкий

5.3 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-22