CamaleonCMS是CamaleonCMS团队的一套基于RubyonRails的高级动态内容管理系统(CMS)。 Camaleon CMS 2.1.2.0 版本到 2.6.0 版本存在安全漏洞,该漏洞源于软件中的媒体上传特性缺少有效的验证与过滤,该特性允许管理用户从外部url获取媒体文件,但无法验证引用到本地主机或其他内部服务器的url。这允许攻击者可利用该漏洞读取存储在内部服务器中的文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| camaleon_cms | camaleon_cms | 2.1.2.0 ~ unspecified | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-25970 | 8.8 HIGH | Camaleon CMS - Insufficient Session Expiration after Password Change |
| CVE-2021-25969 | 6.1 MEDIUM | Camaleon CMS - Stored Cross-Site Scripting (XSS) in Comments |
| CVE-2021-25971 | 4.3 MEDIUM | Camaleon CMS - SVG File Upload Creates DoS for Media Upload Feature |
No comments yet