A Privilege Escalation through a Mass Assignment exists in Camaleon CMS When a user wishes to change his password, the 'updated_ajax' method of the UsersController is called. The vulnerability stems from the use of the dangerous permit! method, which allows all parameters to pass through without any filtering.
https://github.com/Jeanback1/exploit-vault
https://github.com/Jeanback1/CVE-2023-30253-exploit
https://github.com/Jeanback1/CVE-2025-2304-exploit
https://github.com/mattiapertusati/htb-facts
https://github.com/Agentpathogene/CTf-CVE.py
https://github.com/estebanzarate/CVE-2025-2304-Camaleon-CMS-Mass-Assignment-Privilege-Escalation-PoC
https://github.com/MAEN1-prog/maen1-prog.github.io
https://github.com/MAEN1-prog/CVE-2025-2304
https://github.com/popyue/Camaleon-CMS-Exploits
https://github.com/CsuriBird/CVE-2025-2304
https://github.com/sparrowhawk1113/Exploit-for-CVE-2025-2304
https://github.com/predyy/CVE-2025-2304
https://github.com/MatteoLupinacci/PoC4CVEs
Published: 2025-03-14
Updated: 2026-04-15
Base Score: 7.5
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P
Severity: High
Base Score: 8.8
Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity: High
Base Score: 9.4
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Severity: Critical
EPSS: 0.00056