CVE-2025-2304

A Privilege Escalation through a Mass Assignment exists in Camaleon CMS When a user wishes to change his password, the 'updated_ajax' method of the UsersController is called. The vulnerability stems from the use of the dangerous permit! method, which allows all parameters to pass through without any filtering.
CVSS

No CVSS.

Configurations

No configuration.

History

14 Mar 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-14 13:15

Updated : 2025-03-14 13:15


NVD link : CVE-2025-2304

Mitre link : CVE-2025-2304

CVE.ORG link : CVE-2025-2304


JSON object : View

Products Affected

No product.

CWE
CWE-915

Improperly Controlled Modification of Dynamically-Determined Object Attributes