CVE-2025-2304: OWEN2345 Camaleon-CMS
Critical severity, CVSS 9.4. EPSS: 0.6% chance of exploitation in the next 30 days.
A Privilege Escalation through a Mass Assignment exists in Camaleon CMS When a user wishes to change his password, the 'updated_ajax' method of the UsersController is called. The vulnerability stems from the use of the dangerous permit! method, which allows all parameters to pass through without any filtering.
Affected products
- OWEN2345 Camaleon-CMS
Published 2025-03-14. Last modified 2026-06-17.