Skip to content

Commit 2a27689

Browse files
committed
camaleon_cms: 1 new; 1 updated
1 parent 9765962 commit 2a27689

2 files changed

Lines changed: 42 additions & 6 deletions

File tree

‎gems/camaleon_cms/CVE-2024-48652.yml‎

Lines changed: 12 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,21 +2,27 @@
22
gem: camaleon_cms
33
cve: 2024-48652
44
ghsa: hhxg-rvc9-8726
5-
url: https://github.com/paragbagul111/CVE-2024-48652
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2024-48652
66
title: camaleon_cms affected by cross site scripting
77
date: 2024-10-23
88
description: |
99
Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows
1010
remote attacker to execute arbitrary code via the content group
1111
name field.
1212
cvss_v3: 4.8
13-
cvss_v4: 4.8
14-
notes: |
15-
Never patched
16-
17-
Unclear if versions 2.8.0 to 2.8.3 patch this vulnerability.
13+
patched_versions:
14+
- ">= 2.8.0"
1815
related:
1916
url:
2017
- https://nvd.nist.gov/vuln/detail/CVE-2024-48652
18+
- https://rubygems.org/gems/camaleon_cms/versions/2.8.0
19+
- https://github.com/owen2345/camaleon-cms/releases/tag/2.8.0
20+
- https://github.com/owen2345/camaleon-cms/blob/master/CHANGELOG.md#280-2024-07-26
21+
- https://github.com/owen2345/camaleon-cms/compare/2.7.5...2.8.0
22+
- https://github.com/owen2345/camaleon-cms/pull/1075/changes/1de553b759fde08f7b31ef97d41982d47ec3de94
23+
- https://github.com/owen2345/camaleon-cms/pull/1075
2124
- https://github.com/paragbagul111/CVE-2024-48652
2225
- https://github.com/advisories/GHSA-hhxg-rvc9-8726
26+
notes: |
27+
- cvss_v3 from nvd.nist.gov URL
28+
- PR#1075 mentions "content groups"
Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
---
2+
gem: camaleon_cms
3+
cve: 2026-10715
4+
ghsa: vg43-9r8m-q2cc
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2026-10715
6+
title: Camaleon CMS 2.9.2 contains an improper authorization
7+
date: 2026-06-12
8+
description: |
9+
Camaleon CMS 2.9.2 contains an improper authorization vulnerability
10+
in the administrator draft autosave endpoint. A low-privileged
11+
authenticated user can send an arbitrary post_id to
12+
POST /admin/post_type/<POST_TYPE_ID>/drafts and overwrite
13+
the draft associated with another user's post.
14+
cvss_v4: 5.1
15+
unaffected_versions:
16+
- "< 2.9.2"
17+
patched_versions:
18+
- ">= 2.9.4"
19+
related:
20+
url:
21+
- https://nvd.nist.gov/vuln/detail/CVE-2026-10715
22+
- https://rubygems.org/gems/camaleon_cms/versions/2.9.4
23+
- https://github.com/owen2345/camaleon-cms/releases/tag/2.9.4
24+
- https://github.com/owen2345/camaleon-cms/pull/1279/changes/6cffc88599bf9b32850c5ed8b04361b674f0e36d
25+
- https://fluidattacks.com/es/advisories/billie
26+
- https://github.com/advisories/GHSA-vg43-9r8m-q2cc
27+
notes: |
28+
- cvss_v4 from nvd.nist.gov and GHSA URLs.
29+
- Found "draft autosave" in /tag/ URL.
30+
- GHSA is unreviewed.

0 commit comments

Comments
 (0)