CVE-2025-2304:
Camaleon CMS (Create Admin User)
CVE-2025-2304 is a privilege-escalation bug in Camaleon CMS caused by mass assignment in the password-change flow: the updated_ajax UsersController action uses a permissive permit! call, so attacker-supplied fields aren’t properly restricted. An authenticated low-privileged user can abuse this to modify protected account attributes and escalate privileges (e.g., effectively turning themselves into a higher-privilege user/admin), leading to full takeover of the CMS.
Below are general examples of techniques, methods, and proof-of-concept approaches used to demonstrate this vulnerability in a controlled environment.
[*] Logging in as hackindex ... [+] Login successful [+] Got profile page [i] Version detected: 2.9.0 (< 2.9.1) - appears to be vulnerable version [+] authenticity_token: hl5NCx3zaGccGsrK1wcad6m8WCNPMF4L3tec-CSWYJhChP6Gffrguk-RbsLfrCewWZCpGCfidkhmatpJzBBt6w http://facts.htb/admin/users/5/updated_ajax [*] Submitting password change request [+] Submit successful, you should be admin
9.4
Critical risk
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Compexity
low
Privileges
low
Authentication
none
Affected
< 2.9.1
Patched
2.9.1