Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2021-25972
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Camaleon CMS - Server-Side Request Forgery (SSRF) in Media Upload Feature
Source: NVD (National Vulnerability Database)
Vulnerability Description
In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from external URLs but fails to validate URLs referencing to localhost or other internal servers. This allows attackers to read files stored in the internal server.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
服务端请求伪造(SSRF)
Source: NVD (National Vulnerability Database)
Vulnerability Title
CamaleonCMS 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
CamaleonCMS是CamaleonCMS团队的一套基于RubyonRails的高级动态内容管理系统(CMS)。 Camaleon CMS 2.1.2.0 版本到 2.6.0 版本存在安全漏洞,该漏洞源于软件中的媒体上传特性缺少有效的验证与过滤,该特性允许管理用户从外部url获取媒体文件,但无法验证引用到本地主机或其他内部服务器的url。这允许攻击者可利用该漏洞读取存储在内部服务器中的文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
camaleon_cmscamaleon_cms 2.1.2.0 ~ unspecified -
II. Public POCs for CVE-2021-25972
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2021-25972
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2021-25972

No comments yet


Leave a comment