github.com
https://github.com/owen2345/camaleon-cms CVE-2021-25972
MEDIUM
Camaleon CMS - Server-Side Request Forgery (SSRF) in Media Upload Feature
Record summary
CVE-2021-25972 has a selected CVSS score of 4.9 (medium).
Description
In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from external URLs but fails to validate URLs referencing to localhost or other internal servers. This allows attackers to read files stored in the internal server.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
camaleon_cmsBrowse camaleon_cms / camaleon_cms | CVE List | 2.1.2.0 | affected |
| Through 2.6.0 | affected | ||
camaleon_cmsBrowse RubyGems / camaleon_cms | GitHub Advisory | 2.1.2.0 to < 2.6.0.1 · Fixed in 2.6.0.1 | affected |
References
5github.com
https://github.com/owen2345/camaleon-cms/commit/5a252d537411fdd0127714d66c1d76069dc7e190 github.com
https://github.com/rubysec/ruby-advisory-db/blob/master/gems/camaleon_cms/CVE-2021-25972.yml nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-25972 whitesourcesoftware.com
https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25972