Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint
Vulnerability Description
CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter during draft creation. Attackers can submit a malicious HTML payload as a draft title through the drafts creation endpoint, which is persisted to the database without escaping and later rendered as raw HTML in the admin drafts listing, enabling administrator session compromise, cookie theft, and forged authenticated requests.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Owen Peredo Diaz CamaleonCMS 跨站脚本漏洞
Vulnerability Description
Owen Peredo Diaz CamaleonCMS是Owen Peredo Diaz个人开发者的一款内容管理系统。 Owen Peredo Diaz CamaleonCMS 2.9.1及之前版本存在跨站脚本漏洞,该漏洞源于对post title参数输入清理不当,可能允许经过身份验证的低权限用户注入未清理的HTML有效载荷,导致存储型跨站脚本攻击,在管理员浏览器中执行任意JavaScript,造成管理员会话劫持、cookie窃取和伪造认证请求。
CVSS Information
N/A
Vulnerability Type
N/A