In Camaleon CMS, versions 2.0.1 to 2.6.0 are vulnerable to an Uncaught Exception. The apps media upload feature crashes permanently when an attacker with a low privileged access uploads a specially crafted .svg file
The product does not handle or incorrectly handles an exceptional condition.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Camaleon_cms | Tuzitio | 2.0.1 (including) | 2.6.0 (including) |