vendor:
Camaleon CMS
by:
PARAG BAGUL
9.8
CVSS
CRITICAL
Server-Side Template Injection (SSTI)
94
CWE
Product Name: Camaleon CMS
Affected Version From: All versions below 2.7.0
Affected Version To: 2.7.2000
Patch Exists: YES
Related CWE: CVE-2023-30145
CPE: a:camaleon_cms:camaleon_cms:2.7.0
Platforms Tested:
2023
Camaleon CMS v2.7.0 – Server-Side Template Injection (SSTI)
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.
Mitigation:
Update to version 2.7.0 or later.