CVE-2021-47751

CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal sequences to write files outside the intended template directory.
Configurations

No configuration.

History

14 Jan 2026, 20:15

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/50994 - () https://www.exploit-db.com/exploits/50994 -

13 Jan 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 23:15

Updated : 2026-01-14 20:15


NVD link : CVE-2021-47751

Mitre link : CVE-2021-47751

CVE.ORG link : CVE-2021-47751


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')