Camaleon CMS vulnerable to Uncaught Exception
Published: May 24, 2022
SECURITY IDENTIFIERS
- CVE: CVE-2021-25971 (NVD)
- GHSA: GHSA-r2w2-h6r8-3r53
- Vendor Advisory: https://github.com/owen2345/camaleon-cms/commit/ab89584ab32b98a0af3d711e3f508a1d048147d2
GEM
SEVERITY
CVSS v3.x: 4.3 (Medium)
UNAFFECTED VERSIONS
< 2.0.1
PATCHED VERSIONS
>= 2.6.0.1
DESCRIPTION
In Camaleon CMS, versions 2.0.1 through 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file.
