Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript.
References
| Link | Resource |
|---|---|
| https://github.com/owen2345/camaleon-cms | Product |
| https://www.exploit-db.com/exploits/51446 | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/cameleon-cms-authenticated-persistent-cross-site-scripting-via-post-creation | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-12-18 20:15
Updated : 2026-01-16 19:16
NVD link : CVE-2023-53936
Mitre link : CVE-2023-53936
CVE.ORG link : CVE-2023-53936
JSON object : View
Products Affected
tuzitio
- camaleon_cms
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
