Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can supply URLs that pass initial validation but redirect to internal network addresses, allowing server-side request forgery to internal services.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Affected products
owen2345 · CamaleonCMSReferences
https://github.com/owen2345/camaleon-cmshttps://github.com/owen2345/camaleon-cms/blob/2.9.1/app/helpers/camaleon_cms/uploader_helper.rbhttps://github.com/owen2345/camaleon-cms/commit/3c46b6e512518ded476226162305c8eae00aac3fhttps://github.com/owen2345/camaleon-cms/pull/1133https://github.com/owen2345/camaleon-cms/releases/tag/2.9.2https://www.vulncheck.com/advisories/camaleon-cms-2.7.5-through-2.9.1-ssrf-via-http-redirect-in-upload-from-url