Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rp28-mvq3-wf8j

Опубликовано: 14 мар. 2025
Источник: github
Github: Прошло ревью
CVSS4: 9.4

Описание

Camaleon CMS Vulnerable to Privilege Escalation through a Mass Assignment

A Privilege Escalation through a Mass Assignment exists in Camaleon CMS

When a user wishes to change his password, the 'updated_ajax' method of the UsersController is called. The vulnerability stems from the use of the dangerous permit! method, which allows all parameters to pass through without any filtering.

Пакеты

Наименование

camaleon_cms

rubygems
Затронутые версииВерсия исправления

< 2.9.1

2.9.1

EPSS

Процентиль: 24%
0.00081
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-915

Связанные уязвимости

nvd
11 месяцев назад

A Privilege Escalation through a Mass Assignment exists in Camaleon CMS When a user wishes to change his password, the 'updated_ajax' method of the UsersController is called. The vulnerability stems from the use of the dangerous permit! method, which allows all parameters to pass through without any filtering.

EPSS

Процентиль: 24%
0.00081
Низкий

9.4 Critical

CVSS4

Дефекты

CWE-915