VYPR
Unrated severityNVD Advisory· Published Aug 10, 2021· Updated Aug 4, 2024

CVE-2021-37367

CVE-2021-37367

Description

CTparental before 4.45.07 is affected by a code execution vulnerability in the CTparental admin panel. Because The file "bl_categories_help.php" is vulnerable to directory traversal, an attacker can create a file that contains scripts and run arbitrary commands.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

CTparental before 4.45.07 contains a directory traversal in bl_categories_help.php leading to arbitrary command execution by authenticated admins.

Vulnerability

CTparental before version 4.45.07 is affected by a code execution vulnerability in the admin panel. The file bl_categories_help.php is vulnerable to directory traversal, allowing an attacker to create a file containing arbitrary scripts and execute commands [1]. Affected versions include 4.45.02m and all earlier releases up to 4.45.06.

Exploitation

An attacker must have administrative access to the CTparental admin panel. By crafting a directory traversal payload in the bl_categories_help.php file, the attacker can write a script to a location outside the web root and then trigger its execution, leading to command execution [1]. No user interaction other than the attacker's own admin session is required.

Impact

Successful exploitation allows the attacker to execute arbitrary commands on the server with the privileges of the web server user. This results in full compromise of confidentiality, integrity, and availability (CIA) of the CTparental application and potentially the underlying system [1]. The CVSS score for this vulnerability is 7.8 (High).

Mitigation

The vulnerability is fixed in CTparental version 4.45.07 [1]. Users should upgrade to this or any later release. No workaround is mentioned in the available references. Ensure that the admin panel is not exposed to untrusted networks.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.