Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-47751

Опубликовано: 13 янв. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal sequences to write files outside the intended template directory.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:phphtmledit:rich_text_editor:*:*:*:*:*:*:*:*
Версия до 6.6 (включая)

EPSS

Процентиль: 36%
0.00149
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
github
25 дней назад

CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal sequences to write files outside the intended template directory.

EPSS

Процентиль: 36%
0.00149
Низкий

7.5 High

CVSS3

Дефекты

CWE-22