PT-2021-16895 · Unknown · Camaleon Cms
Published
2021-10-20
·
Updated
2023-06-26
·
CVE-2021-25971
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Camaleon CMS versions 2.0.1 through 2.6.0
Description
The media upload feature in Camaleon CMS crashes permanently when an attacker with low privileged access uploads a specially crafted .svg file, resulting in an Uncaught Exception. This issue can be exploited by attackers with limited access, highlighting a potential security risk.
Recommendations
For Camaleon CMS versions 2.0.1 through 2.6.0, consider disabling the media upload feature temporarily to prevent exploitation until a patch is available. Restrict access to the media upload functionality to minimize the risk of crashes caused by specially crafted .svg files.
Exploit
Fix
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Camaleon Cms