RubySec

Providing security resources for the Ruby community

CVE-2018-18260 (camaleon_cms): Camaleon CMS vulnerable to Stored Cross-site Scripting

Camaleon CMS vulnerable to Stored Cross-site Scripting

Published: May 13, 2022

SECURITY IDENTIFIERS

GEM

camaleon_cms

SEVERITY

CVSS v3.x: 6.1 (Medium)

UNAFFECTED VERSIONS

< 2.4

PATCHED VERSIONS

None available.

DESCRIPTION

In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?actions=false.