VDB
Sign up
CRITICAL

GHSA-rp28-mvq3-wf8j

Camaleon CMS Vulnerable to Privilege Escalation through a Mass Assignment

Quick fix

GHSA-rp28-mvq3-wf8j — camaleon_cms: upgrade to the fixed version with the command below.

bundle update camaleon_cms

Details

A Privilege Escalation through a Mass Assignment exists in Camaleon CMS

When a user wishes to change his password, the 'updated_ajax' method of the UsersController is called. The vulnerability stems from the use of the dangerous permit! method, which allows all parameters to pass through without any filtering.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/camaleon_cms
Introduced in: 0Fixed in: 2.9.1
Fixbundle update camaleon_cms

References