Remote Code Execution (RCE) Affecting camaleon_cms package, versions <2.7.4
Threat Intelligence
Exploit Maturity
Mature
EPSS
1.7% (89th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-RUBY-CAMALEONCMS-5660299
- published 28 May 2023
- disclosed 26 May 2023
- credit Parag Bagul
Introduced: 26 May 2023
CVE-2023-30145 Open this link in a new tabHow to fix?
Upgrade camaleon_cms
to version 2.7.4 or higher.
Overview
camaleon_cms is a dynamic and advanced content management system based on Ruby on Rails as an alternative to Wordpress.
Affected versions of this package are vulnerable to Remote Code Execution (RCE) via the formats
parameter.
References
CVSS Scores
version 3.1