RubySec

Providing security resources for the Ruby community

CVE-2024-48652 (camaleon_cms): camaleon_cms affected by cross site scripting

camaleon_cms affected by cross site scripting

Published: October 23, 2024

SECURITY IDENTIFIERS

GEM

camaleon_cms

SEVERITY

CVSS v3.x: 4.8 (Medium)

PATCHED VERSIONS

None available.

DESCRIPTION

Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field.

RELATED