CVE-2021-37367
Description
CTparental before 4.45.07 is affected by a code execution vulnerability in the CTparental admin panel. Because The file "bl_categories_help.php" is vulnerable to directory traversal, an attacker can create a file that contains scripts and run arbitrary commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
CTparental before 4.45.07 contains a directory traversal in bl_categories_help.php leading to arbitrary command execution by authenticated admins.
Vulnerability
CTparental before version 4.45.07 is affected by a code execution vulnerability in the admin panel. The file bl_categories_help.php is vulnerable to directory traversal, allowing an attacker to create a file containing arbitrary scripts and execute commands [1]. Affected versions include 4.45.02m and all earlier releases up to 4.45.06.
Exploitation
An attacker must have administrative access to the CTparental admin panel. By crafting a directory traversal payload in the bl_categories_help.php file, the attacker can write a script to a location outside the web root and then trigger its execution, leading to command execution [1]. No user interaction other than the attacker's own admin session is required.
Impact
Successful exploitation allows the attacker to execute arbitrary commands on the server with the privileges of the web server user. This results in full compromise of confidentiality, integrity, and availability (CIA) of the CTparental application and potentially the underlying system [1]. The CVSS score for this vulnerability is 7.8 (High).
Mitigation
The vulnerability is fixed in CTparental version 4.45.07 [1]. Users should upgrade to this or any later release. No workaround is mentioned in the available references. Ensure that the admin panel is not exposed to untrusted networks.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- CTparental/CTparentaldescription
- Range: <4.45.07
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- gist.github.com/securylight/092ba96a660e07ad76f2a380c2eaa75amitrex_refsource_MISC
News mentions
0No linked articles in our index yet.