CVE-2024-48652

MEDIUM

camaleon_cms 2.7.5 - Stored Cross-Site Scripting via Content Group Name Field

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-48652. PoCs published by paragbagul111.

AI-analyzed exploit summary This repository provides a detailed writeup for CVE-2024-48652, a stored XSS vulnerability in Camaleon CMS v2.7.5. The exploit involves injecting malicious JavaScript into the 'Content Group Name' field, which executes when other users view the affected content.

Description

Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field.

Exploits (1)

nomisec WRITEUP
by paragbagul111 · poc
https://github.com/paragbagul111/CVE-2024-48652

This repository provides a detailed writeup for CVE-2024-48652, a stored XSS vulnerability in Camaleon CMS v2.7.5. The exploit involves injecting malicious JavaScript into the 'Content Group Name' field, which executes when other users view the affected content.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Camaleon CMS v2.7.5
Auth required
Prerequisites: Admin access to Camaleon CMS · Valid session credentials
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1

Scores

CVSS v3 4.8
EPSS 0.3484
EPSS Percentile 97.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
rubygems/camaleon_cms 0RubyGems
tuzitio/camaleon_cms 2.7.5
Published Oct 22, 2024
Tracked Since Feb 18, 2026