CVE-2024-46987 describes a path traversal vulnerability in Camaleon CMS, specifically within the MediaController's download_private_file method. This flaw allows authenticated users to download arbitrary files from the web server, potentially leading to significant information disclosure. Rated 7.7 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N), the vulnerability is easily exploitable over the network with low privileges and no user interaction. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, but users are strongly advised to upgrade to version 2.8.2 to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.8.0, < 2.8.2CPE matchmatch criteria | cpe:2.3:a:tuzitio:camaleon_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.