Record summary

CVE-2021-47751 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.

Description

CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal sequences to write files outside the intended template directory.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 14, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListThrough 6.6affected

Proofs of concept

1

Catalogued exploits

ExploitDBCuteEditor for PHP 6.6 - Directory TraversalExploitDB exploitby Stefan HesselmanNot analyzed1 file
ExploitDB

PoC details

References

4