Vendor Homepageproduct
http://phphtmledit.com/ CVE-2021-47751
MEDIUM
CuteEditor for PHP 6.6 - Directory Traversal
Record summary
CVE-2021-47751 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.
Description
CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal sequences to write files outside the intended template directory.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 14, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CuteEditorBrowse Phphtmledit / CuteEditor | CVE List | Through 6.6 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBCuteEditor for PHP 6.6 - Directory TraversalExploitDB exploitby Stefan HesselmanNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47751 ExploitDB-50994exploit
https://www.exploit-db.com/exploits/50994 VulnCheck Advisory: CuteEditor for PHP 6.6 - Directory TraversalThird-party advisory
https://www.vulncheck.com/advisories/cuteeditor-for-php-directory-traversal