VDB
Sign up
MEDIUM4.8

GHSA-hhxg-rvc9-8726

camaleon_cms affected by cross site scripting

Details

Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/camaleon_cms
Introduced in: 0

No fixed version published yet for camaleon_cms (bundler). Pin to a known-safe version or switch to an alternative.

References