Camaleon CMS 2.9.2 contains an improper authorization...
Moderate severity
Unreviewed
Published
Jun 12, 2026
to the GitHub Advisory Database
•
Updated Jun 12, 2026
Description
Published by the National Vulnerability Database
Jun 12, 2026
Published to the GitHub Advisory Database
Jun 12, 2026
Last updated
Jun 12, 2026
Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-privileged authenticated user can send an arbitrary post_id to POST /admin/post_type/<POST_TYPE_ID>/drafts and overwrite the draft associated with another user's post.
References