Impact
This vulnerability is a stored cross‑site scripting flaw in the cama_contact_form plugin of CamaleonCMS. Attackers with low‑privilege authenticated access can inject arbitrary HTML into the before_html field through the contact form edit endpoint. The unsanitized content is persisted in the database and rendered in the admin interface, causing malicious scripts to execute in the browsers of any user who loads the contact form. The resulting impact includes cookie theft, forged authenticated requests against the admin interface, and session hijacking of viewing users. The designated weakness is CWE‑89.
Affected Systems
The affected product is CamaleonCMS managed by owen2345. The vulnerability exists in the cama_contact_form plugin; no specific version range is provided, so all unpatched installations of this plugin may be impacted.
Risk and Exploitability
The CVSS base score of 9.2 indicates a high‑severity attack with full impact on confidentiality, integrity, and availability. EPSS is not available, but the lack of proper authorization controls allows any user with the ability to edit the contact form to exploit the flaw. The vulnerability is not listed in CISA KEV. Attackers can persist malicious scripts that execute on victims’ browsers, enabling cookie theft, forged requests, and session hijacking, making the risk high for any compromised site.
OpenCVE Enrichment