Record summary

CVE-2021-25972 has a selected CVSS score of 4.9 (medium).

Description

In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from external URLs but fails to validate URLs referencing to localhost or other internal servers. This allows attackers to read files stored in the internal server.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List2.1.2.0affected
Through 2.6.0affected
GitHub Advisory2.1.2.0 to < 2.6.0.1 · Fixed in 2.6.0.1affected

References

5