Camaleon CMS - Server-Side Request Forgery (SSRF) in Media Upload Feature
Vulnerability Description
In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from external URLs but fails to validate URLs referencing to localhost or other internal servers. This allows attackers to read files stored in the internal server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-25972
Credits & Attribution
No credits recorded in the NVD database.
References
More from camaleon_cms
View All →Affected Vendor
camaleon_cms
View all reports →