Описание
Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript.
Ссылки
- Product
- ExploitThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
EPSS
5.4 Medium
CVSS3
4.8 Medium
CVSS3
Дефекты
Связанные уязвимости
Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript.
EPSS
5.4 Medium
CVSS3
4.8 Medium
CVSS3