Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Owen2345
Owen2345 camaleon Cms |
|
| Vendors & Products |
Owen2345
Owen2345 camaleon Cms |
Wed, 12 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are evaluated when an SMTP rejection reflects the recipient address back in the exception message rendered as an inline ERB template. Attackers can submit a crafted email parameter containing ERB expressions through the admin settings test_email endpoint, causing the Rails inline template renderer to evaluate attacker-controlled Ruby code and achieve arbitrary command execution as the Rails process user. | |
| Title | CamaleonCMS 2.9.1 Server-Side Template Injection via test_email Action | |
| Weaknesses | CWE-1336 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-12T19:46:41.784Z
Reserved: 2026-08-11T21:47:14.059Z
Link: CVE-2026-73330
Updated: 2026-08-12T19:46:39.313Z
Status : Received
Published: 2026-08-12T20:17:55.197
Modified: 2026-08-12T20:17:55.197
Link: CVE-2026-73330
No data.
OpenCVE Enrichment
Updated: 2026-08-12T21:30:07Z