Medium severity4.9NVD Advisory· Published Oct 20, 2021· Updated Jun 17, 2026
CVE-2021-25972
CVE-2021-25972
Description
In Camaleon CMS, versions 2.1.2.0 to 2.6.0, are vulnerable to Server-Side Request Forgery (SSRF) in the media upload feature, which allows admin users to fetch media files from external URLs but fails to validate URLs referencing to localhost or other internal servers. This allows attackers to read files stored in the internal server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
camaleon_cmsRubyGems | >= 2.1.2.0, < 2.6.0.1 | 2.6.0.1 |
Affected products
3- camaleon_cms/camaleon_cmsv5Range: 2.1.2.0
Patches
Vulnerability mechanics
References
5- github.com/owen2345/camaleon-cms/commit/5a252d537411fdd0127714d66c1d76069dc7e190nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-vx6p-q4gj-x6xxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-25972ghsaADVISORY
- www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25972nvdThird Party AdvisoryWEB
- github.com/rubysec/ruby-advisory-db/blob/master/gems/camaleon_cms/CVE-2021-25972.ymlghsaWEB
News mentions
0No linked articles in our index yet.