Description
In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?actions=false. NOTE: the vendor reports that they are "unable to reproduce the reported issue on any version."
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7f84-9cqf-g4j9 | Camaleon CMS vulnerable to Stored Cross-site Scripting |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:08:20.377Z
Reserved: 2018-10-11T00:00:00.000Z
Link: CVE-2018-18260
No data.
Status : Modified
Published: 2018-10-15T19:29:02.680
Modified: 2024-11-21T03:55:37.020
Link: CVE-2018-18260
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA