CVE-2024-48652
MEDIUMcamaleon_cms 2.7.5 - Stored Cross-Site Scripting via Content Group Name Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-48652. PoCs published by paragbagul111.
AI-analyzed exploit summary This repository provides a detailed writeup for CVE-2024-48652, a stored XSS vulnerability in Camaleon CMS v2.7.5. The exploit involves injecting malicious JavaScript into the 'Content Group Name' field, which executes when other users view the affected content.
Description
Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field.
Exploits (1)
This repository provides a detailed writeup for CVE-2024-48652, a stored XSS vulnerability in Camaleon CMS v2.7.5. The exploit involves injecting malicious JavaScript into the 'Content Group Name' field, which executes when other users view the affected content.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N