CVE-2021-25969
Camaleon CMS Stored Cross-site Scripting vulnerability
6.1
MEDIUM
CVSS 3.1
EPSS 1.5%
Description
In “Camaleon CMS” application, versions 0.0.1 through 2.6.0 are vulnerable to stored XSS, that allows unprivileged application users to store malicious scripts in the comments section of the post. These scripts are executed in a victim’s browser when they open the page containing the malicious comment.
How to fix CVE-2021-25969
To remediate CVE-2021-25969, upgrade the affected package to a fixed version below.
- —upgrade to 2.6.0.1 or later
Is CVE-2021-25969 being exploited?
Low — EPSS is 1.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 0.0.1, < 2.6.0.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |