{"id":"CVE-2021-25971","details":"In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The app's media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file","aliases":["GHSA-r2w2-h6r8-3r53"],"modified":"2026-04-10T04:31:10.506581Z","published":"2021-10-20T12:15:07.650Z","references":[{"type":"ADVISORY","url":"https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25971"},{"type":"FIX","url":"https://github.com/owen2345/camaleon-cms/commit/ab89584ab32b98a0af3d711e3f508a1d048147d2"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/owen2345/camaleon-cms","events":[{"introduced":"0"},{"last_affected":"8a7e01abdc19a6b6c2b2de6806031c25a529e083"},{"fixed":"ab89584ab32b98a0af3d711e3f508a1d048147d2"}],"database_specific":{"versions":[{"introduced":"2.0.1"},{"last_affected":"2.6.0"}]}}],"versions":["0.1.7","0.2.0","2.1.1","2.1.2","2.1.2.0","2.2.0","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","2.3.6","2.3.7","2.4.0","2.4.1","2.4.2","2.4.3","2.4.3.10","2.4.3.11","2.4.3.12","2.4.3.7","2.4.4","2.4.4.2","2.4.4.3","2.4.4.5","2.4.4.6","2.4.5","2.4.5.1","2.4.5.10","2.4.5.11","2.4.5.12","2.4.5.13","2.4.5.14","2.4.5.7","2.4.6.0","2.4.6.1","2.4.6.7","2.5.1","2.5.3","2.5.3.1","2.6.0","camaleon_cms-2.4.5.11.gem","v2.0.0","v2.1.1.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-25971.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"}]}