← volver
CVE-2026-10715

Camaleon CMS 2.9.2 - Improper authorization in draft autosave endpoint

CVSS 5.1 MEDIUMEPSS 0.2%CWE-862
Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-privileged authenticated user can send an arbitrary post_id to POST /admin/post_type/<POST_TYPE_ID>/drafts and overwrite the draft associated with another user's post.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Productos afectados
Camaleon CMS · Camaleon CMS

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →