We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 3986f1d commit c105c3fCopy full SHA for c105c3f
gems/camaleon_cms/CVE-2024-48652.yml
@@ -0,0 +1,21 @@
1
+---
2
+gem: camaleon_cms
3
+cve: 2024-48652
4
+ghsa: hhxg-rvc9-8726
5
+url: https://github.com/paragbagul111/CVE-2024-48652
6
+title: camaleon_cms affected by cross site scripting
7
+date: 2024-10-23
8
+description: |
9
+ Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows
10
+ remote attacker to execute arbitrary code via the content group
11
+ name field.
12
+cvss_v3: 4.8
13
+notes: |
14
+ Never patched
15
+
16
+ Unclear if versions 2.8.0 to 2.8.3 patch this vulnerability.
17
+related:
18
+ url:
19
+ - https://nvd.nist.gov/vuln/detail/CVE-2024-48652
20
+ - https://github.com/paragbagul111/CVE-2024-48652
21
+ - https://github.com/advisories/GHSA-hhxg-rvc9-8726
0 commit comments