Описание
In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 2.0.1 (включая) до 2.6.0 (включая)
cpe:2.3:a:tuzitio:camaleon_cms:*:*:*:*:*:*:*:*
EPSS
Процентиль: 59%
0.00389
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-248
CWE-755
Связанные уязвимости
EPSS
Процентиль: 59%
0.00389
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-248
CWE-755