CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate plugin configuration parameters at runtime across the attack, front_cache, cama_meta_tag, and cama_contact_form plugins to alter cached page behavior, modify public meta-tag output, or reconfigure contact forms, enabling account takeover when chained with stored cross-site scripting through the contact form's before_html field.
References
Configurations
No configuration.
History
12 Aug 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-08-12 20:17
Updated : 2026-08-12 20:17
NVD link : CVE-2026-73326
Mitre link : CVE-2026-73326
CVE.ORG link : CVE-2026-73326
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
