RubySec

Providing security resources for the Ruby community

CVE-2021-25971 (camaleon_cms): Camaleon CMS vulnerable to Uncaught Exception

ADVISORIES

GEM

camaleon_cms

SEVERITY

CVSS v3.x: 4.3 (Medium)

UNAFFECTED VERSIONS

  • < 2.0.1

PATCHED VERSIONS

  • >= 2.6.0.1

DESCRIPTION

In Camaleon CMS, versions 2.0.1 through 2.6.0 are vulnerable to an Uncaught Exception. The app’s media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file.

RELATED