Vendor
high
advisory
Stored Cross-Site Scripting in CamaleonCMS cama_contact_form Plugin
2 TTPs 1 CVEAn authenticated stored cross-site scripting vulnerability in the CamaleonCMS cama_contact_form plugin allows attackers to inject malicious HTML and JavaScript, enabling session takeover and unauthorized administrative actions.
cama_contact_form
2t
1c
high
advisory
Privilege Escalation via IDOR in CamaleonCMS
1 rule 3 TTPs 1 CVECamaleonCMS versions 2.9.2 and earlier are vulnerable to privilege escalation via an IDOR parameter confusion flaw in the UsersController, allowing authenticated attackers to overwrite arbitrary user credentials.
CamaleonCMS
web-application
xss
injection
1r
3t
1c
updated