Описание
Camaleon CMS vulnerable to Uncaught Exception
In Camaleon CMS, versions 2.0.1 through 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2021-25971
- https://github.com/owen2345/camaleon-cms/commit/ab89584ab32b98a0af3d711e3f508a1d048147d2
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/camaleon_cms/CVE-2021-25971.yml
- https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25971
Пакеты
Наименование
camaleon_cms
rubygems
Затронутые версииВерсия исправления
>= 2.0.1, < 2.6.0.1
2.6.0.1
Связанные уязвимости
CVSS3: 4.3
nvd
больше 4 лет назад
In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file