CVE-2021-25972
Last modified
CVE-2021-25972 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from external URLs but fails to validate URLs referencing to localhost or other internal servers. This allows attackers to read files stored in the internal server.. EPSS estimates a 0.95% chance of exploitation in the next 30 days.
Description
In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from external URLs but fails to validate URLs referencing to localhost or other internal servers. This allows attackers to read files stored in the internal server.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tuzitio | Camaleon Cms | >= 2.1.2.0, <= 2.6.0 |
References
- https://github.com/owen2345/camaleon-cms/commit/5a252d537411fdd0127714d66c1d76069dc7e190Patch, Third Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25972Third Party Advisory
- https://github.com/owen2345/camaleon-cms/commit/5a252d537411fdd0127714d66c1d76069dc7e190Patch, Third Party Advisory
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25972Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-25972?
How severe is CVE-2021-25972?
How do I fix CVE-2021-25972?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-25966In “Orchard core CMS” application, versions 1.0.0-beta1-3383…8.8
- CVE-2021-25967In CKAN, versions 2.9.0 to 2.9.3 are affected by a stored XS…5.4
- CVE-2021-25968In “OpenCMS”, versions 10.5.0 to 11.0.2 are affected by a st…5.4
- CVE-2021-25969In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vul…6.1
- CVE-2021-25970Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active ses…8.8
- CVE-2021-25971In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to a…4.3
- CVE-2021-25973In Publify, 9.0.0.pre1 to 9.2.4 are vulnerable to Improper A…6.5
- CVE-2021-25974In Publify, versions v8.0 to v9.2.4 are vulnerable to stored…5.4
- CVE-2021-25975In publify, versions v8.0 to v9.2.4 are vulnerable to stored…5.4
- CVE-2021-25976In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable…8.1
- CVE-2021-25977In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to sto…5.4
- CVE-2021-25978Apostrophe CMS versions between 2.63.0 to 3.3.1 are vulnerab…5.4
Are you affected by CVE-2021-25972?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
