Launch Week Day 1: Announcing Security Design Review
UNKNOWN RubyGems

Camaleon CMS Vulnerable to Privilege Escalation through a Mass Assignment

GHSA-rp28-mvq3-wf8j · CVE-2025-2304

Published · Modified

Description

A Privilege Escalation through a Mass Assignment exists in Camaleon CMS

When a user wishes to change his password, the 'updated_ajax' method of the UsersController is called. The vulnerability stems from the use of the dangerous permit! method, which allows all parameters to pass through without any filtering.

Ready to move

Start Securing

Free, no credit card | First findings in minutes