{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/cama_contact_form/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.7,"id":"CVE-2026-73332"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cama_contact_form"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["CamaleonCMS"],"content_html":"\u003cp\u003eCamaleonCMS contains a stored cross-site scripting (XSS) vulnerability (CVE-2026-73332) within the cama_contact_form plugin. The vulnerability arises from improper input sanitization and insufficient authorization controls on the contact form edit endpoint. Authenticated attackers with low-level privileges can submit arbitrary HTML and JavaScript payloads into the 'before_html' field, which are stored in the application database without adequate validation. When administrators or other users view the contact form, the injected scripts execute within the context of their browsers. This flaw facilitates the theft of session cookies, the execution of unauthorized administrative operations, and full session hijacking, posing a significant risk to the integrity and confidentiality of the affected CMS environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows authenticated attackers to elevate their impact by compromising higher-privileged users. The impact includes unauthorized access to administrative functions, potential data exfiltration via forged authenticated requests, and the persistent execution of malicious code in the browsers of users interacting with the CMS.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit all CamaleonCMS instances for unauthorized modifications to the 'before_html' configuration in contact forms.\u003c/li\u003e\n\u003cli\u003eImplement strict server-side input validation and output encoding for all user-controllable fields within the cama_contact_form plugin.\u003c/li\u003e\n\u003cli\u003eReview access control lists for the contact form edit endpoint to ensure that only authorized administrative roles can modify form configuration settings.\u003c/li\u003e\n\u003cli\u003eApply patches provided by the CamaleonCMS vendor to address CVE-2026-73332 immediately.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T20:58:52Z","date_published":"2026-08-12T20:58:52Z","id":"https://feed.craftedsignal.io/briefs/2026-08-camaleon-cms-xss/","summary":"An authenticated stored cross-site scripting vulnerability in the CamaleonCMS cama_contact_form plugin allows attackers to inject malicious HTML and JavaScript, enabling session takeover and unauthorized administrative actions.","title":"Stored Cross-Site Scripting in CamaleonCMS cama_contact_form Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-camaleon-cms-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cama_contact_form","version":"https://jsonfeed.org/version/1.1"}