Skip to content

Commit 9ef1686

Browse files
jasnowRubySec CI
authored and
RubySec CI
committed
Updated advisory posts against rubysec/ruby-advisory-db@c105c3f
1 parent 856b643 commit 9ef1686

File tree

1 file changed

+28
-0
lines changed

1 file changed

+28
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
---
2+
layout: advisory
3+
title: 'CVE-2024-48652 (camaleon_cms): camaleon_cms affected by cross site scripting'
4+
comments: false
5+
categories:
6+
- camaleon_cms
7+
advisory:
8+
gem: camaleon_cms
9+
cve: 2024-48652
10+
ghsa: hhxg-rvc9-8726
11+
url: https://github.com/paragbagul111/CVE-2024-48652
12+
title: camaleon_cms affected by cross site scripting
13+
date: 2024-10-23
14+
description: |
15+
Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows
16+
remote attacker to execute arbitrary code via the content group
17+
name field.
18+
cvss_v3: 4.8
19+
notes: |
20+
Never patched
21+
22+
Unclear if versions 2.8.0 to 2.8.3 patch this vulnerability.
23+
related:
24+
url:
25+
- https://nvd.nist.gov/vuln/detail/CVE-2024-48652
26+
- https://github.com/paragbagul111/CVE-2024-48652
27+
- https://github.com/advisories/GHSA-hhxg-rvc9-8726
28+
---

0 commit comments

Comments
 (0)