Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.1 RubyGems

Camaleon CMS Stored Cross-site Scripting vulnerability

GHSA-x78v-4fvj-rg9j · CVE-2021-25969

Published · Modified

Description

In “Camaleon CMS” application, versions 0.0.1 through 2.6.0 are vulnerable to stored XSS, that allows unprivileged application users to store malicious scripts in the comments section of the post. These scripts are executed in a victim’s browser when they open the page containing the malicious comment.

Ready to move

Start Securing

Free, no credit card | First findings in minutes