Camaleon CMS vulnerable to Stored Cross-site Scripting
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Mar 6, 2023
Description
Published by the National Vulnerability Database
Oct 15, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jan 24, 2023
Last updated
Mar 6, 2023
In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via
/admin/media/upload?actions=false
.References