Stored Cross-Site Scripting in Camaleon CMS 2.4 by Camaleon
CVE-2018-18260
6.1MEDIUM
What is CVE-2018-18260?
Camaleon CMS version 2.4 is susceptible to a Stored Cross-Site Scripting vulnerability that arises in the user settings section, specifically during the profile image upload process via the upload endpoint. This flaw allows an attacker to inject malicious scripts that may execute in the context of another user's browser session, potentially compromising user data and privacy. Although the vendor reports challenges in reproducing the issue, the risk associated with unvalidated inputs remains a significant concern for users and administrators seeking to maintain the integrity of their systems.
