From 2a27689b0c52c8d09524ca30e3638ab35413de74 Mon Sep 17 00:00:00 2001 From: Al Snow <43523+jasnow@users.noreply.github.com> Date: Sat, 3 Oct 2026 14:40:37 -0400 Subject: [PATCH] camaleon_cms: 1 new; 1 updated --- gems/camaleon_cms/CVE-2024-48652.yml | 18 +++++++++++------ gems/camaleon_cms/CVE-2026-10715.yml | 30 ++++++++++++++++++++++++++++ 2 files changed, 42 insertions(+), 6 deletions(-) create mode 100644 gems/camaleon_cms/CVE-2026-10715.yml diff --git a/gems/camaleon_cms/CVE-2024-48652.yml b/gems/camaleon_cms/CVE-2024-48652.yml index 6b44354e0d..4c4d2c2a1c 100644 --- a/gems/camaleon_cms/CVE-2024-48652.yml +++ b/gems/camaleon_cms/CVE-2024-48652.yml @@ -2,7 +2,7 @@ gem: camaleon_cms cve: 2024-48652 ghsa: hhxg-rvc9-8726 -url: https://github.com/paragbagul111/CVE-2024-48652 +url: https://nvd.nist.gov/vuln/detail/CVE-2024-48652 title: camaleon_cms affected by cross site scripting date: 2024-10-23 description: | @@ -10,13 +10,19 @@ description: | remote attacker to execute arbitrary code via the content group name field. cvss_v3: 4.8 -cvss_v4: 4.8 -notes: | - Never patched - - Unclear if versions 2.8.0 to 2.8.3 patch this vulnerability. +patched_versions: + - ">= 2.8.0" related: url: - https://nvd.nist.gov/vuln/detail/CVE-2024-48652 + - https://rubygems.org/gems/camaleon_cms/versions/2.8.0 + - https://github.com/owen2345/camaleon-cms/releases/tag/2.8.0 + - https://github.com/owen2345/camaleon-cms/blob/master/CHANGELOG.md#280-2024-07-26 + - https://github.com/owen2345/camaleon-cms/compare/2.7.5...2.8.0 + - https://github.com/owen2345/camaleon-cms/pull/1075/changes/1de553b759fde08f7b31ef97d41982d47ec3de94 + - https://github.com/owen2345/camaleon-cms/pull/1075 - https://github.com/paragbagul111/CVE-2024-48652 - https://github.com/advisories/GHSA-hhxg-rvc9-8726 +notes: | + - cvss_v3 from nvd.nist.gov URL + - PR#1075 mentions "content groups" diff --git a/gems/camaleon_cms/CVE-2026-10715.yml b/gems/camaleon_cms/CVE-2026-10715.yml new file mode 100644 index 0000000000..a46d606491 --- /dev/null +++ b/gems/camaleon_cms/CVE-2026-10715.yml @@ -0,0 +1,30 @@ +--- +gem: camaleon_cms +cve: 2026-10715 +ghsa: vg43-9r8m-q2cc +url: https://nvd.nist.gov/vuln/detail/CVE-2026-10715 +title: Camaleon CMS 2.9.2 contains an improper authorization +date: 2026-06-12 +description: | + Camaleon CMS 2.9.2 contains an improper authorization vulnerability + in the administrator draft autosave endpoint. A low-privileged + authenticated user can send an arbitrary post_id to + POST /admin/post_type//drafts and overwrite + the draft associated with another user's post. +cvss_v4: 5.1 +unaffected_versions: + - "< 2.9.2" +patched_versions: + - ">= 2.9.4" +related: + url: + - https://nvd.nist.gov/vuln/detail/CVE-2026-10715 + - https://rubygems.org/gems/camaleon_cms/versions/2.9.4 + - https://github.com/owen2345/camaleon-cms/releases/tag/2.9.4 + - https://github.com/owen2345/camaleon-cms/pull/1279/changes/6cffc88599bf9b32850c5ed8b04361b674f0e36d + - https://fluidattacks.com/es/advisories/billie + - https://github.com/advisories/GHSA-vg43-9r8m-q2cc +notes: | + - cvss_v4 from nvd.nist.gov and GHSA URLs. + - Found "draft autosave" in /tag/ URL. + - GHSA is unreviewed.