CVE-2021-47751

CuteEditor for PHP (now referred to as Rich Text Editor) 6.6 contains a directory traversal vulnerability in the browse template feature that allows attackers to write files to arbitrary web root directories. Attackers can exploit the ServerMapPath() function by renaming uploaded HTML files using directory traversal sequences to write files outside the intended template directory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:phphtmledit:rich_text_editor:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-13 23:15

Updated : 2026-02-02 16:16


NVD link : CVE-2021-47751

Mitre link : CVE-2021-47751

CVE.ORG link : CVE-2021-47751


JSON object : View

Products Affected

phphtmledit

  • rich_text_editor
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')