Record summary

CVE-2021-25970 has a selected CVSS score of 8.8 (high).

Description

Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List0.1.7affected
Through 2.6.0affected
GitHub Advisory0.1.7 to < 2.6.0.1 · Fixed in 2.6.0.1affected

References

5