CVE-2021-25971
Last modified
CVE-2021-25971 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file. EPSS estimates a 0.98% chance of exploitation in the next 30 days.
Description
In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tuzitio | Camaleon Cms | >= 2.0.1, <= 2.6.0 |
References
- https://github.com/owen2345/camaleon-cms/commit/ab89584ab32b98a0af3d711e3f508a1d048147d2Patch, Third Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25971Third Party Advisory
- https://github.com/owen2345/camaleon-cms/commit/ab89584ab32b98a0af3d711e3f508a1d048147d2Patch, Third Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25971Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-25971?
How severe is CVE-2021-25971?
How do I fix CVE-2021-25971?
Are you affected by CVE-2021-25971?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
