383
VMScore

CVE-2018-18260

Published: 15/10/2018 Updated: 17/05/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?actions=false. NOTE: the vendor reports that they are "unable to reproduce the reported issue on any version."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tuzitio camaleon cms 2.4.0

Exploits

CAMALEON CMS version 24 suffers from a cross site scripting vulnerability ...