GHSL-2024-186: GHSL-2024-182_GHSL-2024-186: Several vulnerabilities (RCE, XSS) in Camaleon CMS - CVE-2024-46986, CVE-2024-46987
Several vulnerabilities were found in Camaleon CMS. Three vulnerabilities (GHSL-2024-182, GHSL-2024-183, GHSL-2024-184) can be exploited by “normal” authenticated users. Camaleon CMS instances where self-registration is enabled (e.g. to leave comments on posts) are especially endangered by these vulnerabilities.
Affected Software
Event History
Frequently Asked Questions
What types of vulnerabilities are identified in GHSL-2024-186?
GHSL-2024-186 identifies several vulnerabilities in Camaleon CMS, including Remote Code Execution (RCE) and Cross-Site Scripting (XSS).
What is the risk level associated with GHSL-2024-186?
The risk level associated with GHSL-2024-186 is rated at 66, indicating a significant threat to affected systems.
How can I mitigate the vulnerabilities described in GHSL-2024-186?
To mitigate the vulnerabilities in GHSL-2024-186, it is recommended to update Camaleon CMS to the latest version where these vulnerabilities are patched.
Who is most at risk due to the vulnerabilities in GHSL-2024-186?
Users of Camaleon CMS who have enabled self-registration features are particularly at risk from the vulnerabilities outlined in GHSL-2024-186.
Are there any known exploits for the vulnerabilities in GHSL-2024-186?
Yes, the vulnerabilities in GHSL-2024-186 can be exploited by authenticated users, highlighting the importance of immediate remediation.