CVE-2021-25971

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/10/2021
Last modified:
26/06/2023

Description

In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:tuzitio:camaleon_cms:*:*:*:*:*:*:*:* 2.0.1 (including) 2.6.0 (including)