logo

CVE-2021-25969 camaleon_cms

Package

Manager: gem
Name: camaleon_cms
Vulnerable Version: >=0.0.1 <2.6.0.1

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.01844 pctl0.82276

Details

Camaleon CMS Stored Cross-site Scripting vulnerability In “Camaleon CMS” application, versions 0.0.1 through 2.6.0 are vulnerable to stored XSS, that allows unprivileged application users to store malicious scripts in the comments section of the post. These scripts are executed in a victim’s browser when they open the page containing the malicious comment.

Metadata

Created: 2022-05-24T22:33:54Z
Modified: 2023-01-26T23:54:19Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x78v-4fvj-rg9j/GHSA-x78v-4fvj-rg9j.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-x78v-4fvj-rg9j
Finding: F425
Auto approve: 1