Impact
CamaleonCMS has a stored cross‑site scripting flaw that lets an authenticated low‑privileged user insert unfiltered HTML into a post title field when creating a draft. The payload is saved in the database and later rendered as raw HTML in the administrator drafts list, allowing attacker‑controlled JavaScript to run in the admin browser. This can be used to steal administrator session cookies, hijack the session, and perform actions as the admin without further authentication.
Affected Systems
The affected product is CamaleonCMS developed by owen2345. No specific version range is listed in the data, so all installations of the CMS may be vulnerable until a patch is applied.
Risk and Exploitability
With a CVSS score of 9.2 the vulnerability is critical. The EPSS score is not available and the issue is not in the CISA KEV catalog, but the impact level is high. Attackers must be authenticated with low privileges, which is a relatively low barrier in many sites that provide user accounts. Once a malicious draft title is created, any administrator who views the drafts list will execute the code, potentially compromising the entire CMS instance.
OpenCVE Enrichment