Persistent Cross-Site Scripting Vulnerability in Cameleon CMS by Cameleon
CVE-2023-53936
Key Information:
- Vendor
Tuzitio
- Status
- Vendor
- CVE Published:
- 18 December 2025
Badges
What is CVE-2023-53936?
The Cameleon CMS version 2.7.4 contains a persistent cross-site scripting vulnerability that enables authenticated administrators to inject malicious scripts into post titles. Attackers can craft posts that contain embedded SVG scripts. When other users hover over the post title, these scripts execute, posing a significant risk of stealing session cookies and allowing the execution of arbitrary JavaScript. This vulnerability underscores the importance of secure coding practices to prevent such script injection attacks.
Affected Version(s)
Cameleon CMS 2.7.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
