{"id":"CVE-2025-2304","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-2304","summary":"Camaleon CMS Vulnerable to Privilege Escalation through a Mass Assignment","details":"A Privilege Escalation through a Mass Assignment exists in Camaleon CMS\n\nWhen a user wishes to change his password, the 'updated_ajax' method of the UsersController is called. The vulnerability stems from the use of the dangerous permit! method, which allows all parameters to pass through without any filtering.","published":"2025-03-14T15:32:03Z","modified":"2025-03-19T15:46:58.677792Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":5,"affectedPackages":[{"ecosystem":"RubyGems","name":"camaleon_cms","fixedVersion":"2.9.1"}],"fix":{"url":"https://github.com/owen2345/camaleon-cms/pull/1109","label":"owen2345/camaleon-cms#1109"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-2304"},{"type":"WEB","url":"https://github.com/owen2345/camaleon-cms/pull/1109"},{"type":"WEB","url":"https://github.com/owen2345/camaleon-cms/commit/179fd6b1ecf258d3e214aebfa87ac4a322ea4db4"},{"type":"PACKAGE","url":"https://github.com/owen2345/camaleon-cms"},{"type":"WEB","url":"https://github.com/owen2345/camaleon-cms/releases/tag/2.9.1"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/camaleon_cms/CVE-2025-2304.yml"},{"type":"WEB","url":"https://www.tenable.com/security/research/tra-2025-09"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-03-19T15:46:58.677792Z"}}