PT-2026-71258 · Unknown · Camaleon Cms
CVE-2026-73326
·
Published
2026-08-12
·
Updated
2026-08-12
CVSS v3.1
7.6
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
CamaleonCMS (affected versions not specified)
Description
Missing authorization allows authenticated low-privileged users to access and modify plugin settings via four unprotected plugin-administration endpoints. This allows the manipulation of configuration parameters at runtime for the
front cache, cama meta tag, and cama contact form plugins. Such actions can alter cached page behavior, modify public meta-tag output, or reconfigure contact forms. When combined with stored cross-site scripting (XSS)—a technique where malicious scripts are permanently stored on the target server—via the before html field of the contact form, this can lead to account takeover.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Camaleon Cms