File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -8,22 +8,28 @@ advisory:
88 gem : camaleon_cms
99 cve : 2024-48652
1010 ghsa : hhxg-rvc9-8726
11- url : https://github.com/paragbagul111 /CVE-2024-48652
11+ url : https://nvd.nist.gov/vuln/detail /CVE-2024-48652
1212 title : camaleon_cms affected by cross site scripting
1313 date : 2024-10-23
1414 description : |-
1515 Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows
1616 remote attacker to execute arbitrary code via the content group
1717 name field.
1818 cvss_v3 : 4.8
19- cvss_v4 : 4.8
20- notes : |
21- Never patched
22-
23- Unclear if versions 2.8.0 to 2.8.3 patch this vulnerability.
19+ patched_versions :
20+ - " >= 2.8.0"
2421 related :
2522 url :
2623 - https://nvd.nist.gov/vuln/detail/CVE-2024-48652
24+ - https://rubygems.org/gems/camaleon_cms/versions/2.8.0
25+ - https://github.com/owen2345/camaleon-cms/releases/tag/2.8.0
26+ - https://github.com/owen2345/camaleon-cms/blob/master/CHANGELOG.md#280-2024-07-26
27+ - https://github.com/owen2345/camaleon-cms/compare/2.7.5...2.8.0
28+ - https://github.com/owen2345/camaleon-cms/pull/1075/changes/1de553b759fde08f7b31ef97d41982d47ec3de94
29+ - https://github.com/owen2345/camaleon-cms/pull/1075
2730 - https://github.com/paragbagul111/CVE-2024-48652
2831 - https://github.com/advisories/GHSA-hhxg-rvc9-8726
32+ notes : |
33+ - cvss_v3 from nvd.nist.gov URL
34+ - PR#1075 mentions "content groups"
2935---
Original file line number Diff line number Diff line change 1+ ---
2+ layout : advisory
3+ title : ' CVE-2026-10715 (camaleon_cms): Camaleon CMS 2.9.2 contains an improper authorization'
4+ comments : false
5+ categories :
6+ - camaleon_cms
7+ advisory :
8+ gem : camaleon_cms
9+ cve : 2026-10715
10+ ghsa : vg43-9r8m-q2cc
11+ url : https://nvd.nist.gov/vuln/detail/CVE-2026-10715
12+ title : Camaleon CMS 2.9.2 contains an improper authorization
13+ date : 2026-06-12
14+ description : |-
15+ Camaleon CMS 2.9.2 contains an improper authorization vulnerability
16+ in the administrator draft autosave endpoint. A low-privileged
17+ authenticated user can send an arbitrary post_id to
18+ POST /admin/post_type/<POST_TYPE_ID>/drafts and overwrite
19+ the draft associated with another user's post.
20+ cvss_v4 : 5.1
21+ unaffected_versions :
22+ - " < 2.9.2"
23+ patched_versions :
24+ - " >= 2.9.3"
25+ related :
26+ url :
27+ - https://nvd.nist.gov/vuln/detail/CVE-2026-10715
28+ - https://rubygems.org/gems/camaleon_cms/versions/2.9.3
29+ - https://github.com/owen2345/camaleon-cms/releases/tag/2.9.3
30+ - https://github.com/owen2345/camaleon-cms/pull/1196
31+ - https://fluidattacks.com/es/advisories/billie
32+ - https://github.com/advisories/GHSA-vg43-9r8m-q2cc
33+ notes : |
34+ - cvss_v4 from nvd.nist.gov and GHSA URLs.
35+ - Found PR#1196 in release URL.
36+ - GHSA is unreviewed.
37+ ---
You can’t perform that action at this time.
0 commit comments