Executive brief
CamaleonCMS is a content management system built on Ruby on Rails. A missing authorization check in the admin users controller allows any authenticated user to view profile data of other users, including administrators, by simply requesting different user IDs. An attacker with any valid login can enumerate all user accounts and expose sensitive profile information without proper permission checks.
Technical details
This is an insecure direct object reference (IDOR) vulnerability in the Admin::UsersController#profile action. The profile action was excluded from the role validation filter and lacks an ownership check, allowing any authenticated user to access arbitrary user profiles by supplying enumerable sequential integer user IDs. An attacker can send GET requests to the admin profile endpoint with different user ID parameters to disclose profile information of any user. The vulnerability is fixed by adding an inline authorize! check in the profile action to verify that the requesting user has permission to view the target user's profile.
Affected products
- CamaleonCMS CamaleonCMS 2.9.2 and earlier
Timeline
- 2026-08-11: disclosed
- 2026-07-12: patched: Security fix merged in PR #1197