{"id":"CVE-2025-2304","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-2304","summary":"A Privilege Escalation through a Mass Assignment exists in Camaleon CMS\n\nWhen a user wishes to change his password, the 'updated_ajax' method of the UsersController is called. The vulnerability…","details":"A Privilege Escalation through a Mass Assignment exists in Camaleon CMS\n\nWhen a user wishes to change his password, the 'updated_ajax' method of the UsersController is called. The vulnerability stems from the use of the dangerous permit! method, which allows all parameters to pass through without any filtering.","published":"2025-03-14T13:15:41.160","modified":"2026-06-17T09:06:43.410","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":5,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/owen2345/camaleon-cms"},{"type":"WEB","url":"https://www.tenable.com/security/research/tra-2025-09"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T09:06:43.410"}}