PT-2021-16895 · Unknown · Camaleon Cms

Published

2021-10-20

·

Updated

2023-06-26

·

CVE-2021-25971

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Camaleon CMS versions 2.0.1 through 2.6.0
Description The media upload feature in Camaleon CMS crashes permanently when an attacker with low privileged access uploads a specially crafted .svg file, resulting in an Uncaught Exception. This issue can be exploited by attackers with limited access, highlighting a potential security risk.
Recommendations For Camaleon CMS versions 2.0.1 through 2.6.0, consider disabling the media upload feature temporarily to prevent exploitation until a patch is available. Restrict access to the media upload functionality to minimize the risk of crashes caused by specially crafted .svg files.

Exploit

Fix

Improper Handling of Exceptional Conditions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25971
GHSA-R2W2-H6R8-3R53

Affected Products

Camaleon Cms