GHSA-7f84-9cqf-g4j9

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-7f84-9cqf-g4j9/GHSA-7f84-9cqf-g4j9.json
Aliases
  • CVE-2018-18260
Published
2022-05-13T01:05:37Z
Modified
2023-01-24T16:02:02Z
Details

In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?actions=false.

References

Affected packages

RubyGems / camaleon_cms

camaleon_cms

Affected ranges

Affected versions

2.*

2.4