CVE-2021-25969 – camaleon_cms
Package
Manager: gem
Name: camaleon_cms
Vulnerable Version: >=0.0.1 <2.6.0.1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS: 0.01844 pctl0.82276
Details
Camaleon CMS Stored Cross-site Scripting vulnerability In “Camaleon CMS” application, versions 0.0.1 through 2.6.0 are vulnerable to stored XSS, that allows unprivileged application users to store malicious scripts in the comments section of the post. These scripts are executed in a victim’s browser when they open the page containing the malicious comment.
Metadata
Created: 2022-05-24T22:33:54Z
Modified: 2023-01-26T23:54:19Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x78v-4fvj-rg9j/GHSA-x78v-4fvj-rg9j.json
CWE IDs: ["CWE-79"]
Alternative ID: GHSA-x78v-4fvj-rg9j
Finding: F425
Auto approve: 1