Camaleon CMS - SVG File Upload Creates DoS for Media Upload Feature
CVE-2021-25971
4.3MEDIUM
What is CVE-2021-25971?
In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file
Affected Version(s)
camaleon_cms 2.0.1
camaleon_cms <= 2.6.0
