CRITICAL
GHSA-rp28-mvq3-wf8j
Camaleon CMS Vulnerable to Privilege Escalation through a Mass Assignment
Quick fix
GHSA-rp28-mvq3-wf8j — camaleon_cms: upgrade to the fixed version with the command below.
bundle update camaleon_cmsDetails
A Privilege Escalation through a Mass Assignment exists in Camaleon CMS
When a user wishes to change his password, the 'updated_ajax' method of the UsersController is called. The vulnerability stems from the use of the dangerous permit! method, which allows all parameters to pass through without any filtering.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-2304[ADVISORY]
- https://github.com/owen2345/camaleon-cms/pull/1109[WEB]
- https://github.com/owen2345/camaleon-cms/commit/179fd6b1ecf258d3e214aebfa87ac4a322ea4db4[WEB]
- https://github.com/owen2345/camaleon-cms[PACKAGE]
- https://github.com/owen2345/camaleon-cms/releases/tag/2.9.1[WEB]
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/camaleon_cms/CVE-2025-2304.yml[WEB]
- https://www.tenable.com/security/research/tra-2025-09[WEB]