Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.3 RubyGems

Camaleon CMS vulnerable to Uncaught Exception

GHSA-r2w2-h6r8-3r53 · CVE-2021-25971

Published · Modified

Description

In Camaleon CMS, versions 2.0.1 through 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file.

Ready to move

Start Securing

Free, no credit card | First findings in minutes