Skip to content

Commit c105c3f

Browse files
jasnowpostmodern
authored andcommitted
GHSA SYNC: 1 brand new advisory
1 parent 3986f1d commit c105c3f

File tree

1 file changed

+21
-0
lines changed

1 file changed

+21
-0
lines changed

gems/camaleon_cms/CVE-2024-48652.yml

+21
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
---
2+
gem: camaleon_cms
3+
cve: 2024-48652
4+
ghsa: hhxg-rvc9-8726
5+
url: https://github.com/paragbagul111/CVE-2024-48652
6+
title: camaleon_cms affected by cross site scripting
7+
date: 2024-10-23
8+
description: |
9+
Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows
10+
remote attacker to execute arbitrary code via the content group
11+
name field.
12+
cvss_v3: 4.8
13+
notes: |
14+
Never patched
15+
16+
Unclear if versions 2.8.0 to 2.8.3 patch this vulnerability.
17+
related:
18+
url:
19+
- https://nvd.nist.gov/vuln/detail/CVE-2024-48652
20+
- https://github.com/paragbagul111/CVE-2024-48652
21+
- https://github.com/advisories/GHSA-hhxg-rvc9-8726

0 commit comments

Comments
 (0)