CVE-2021-25972

Published
View on NVD ↗
CVSS v3
4.9
MEDIUM
CVSS v2
4
MEDIUM
Affected
1
PROJECT

Description

In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from external URLs but fails to validate URLs referencing to localhost or other internal servers. This allows attackers to read files stored in the internal server.

Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails
GitHubGitHub
1.24K