Executive brief
CamaleonCMS is a Ruby on Rails-based content management system used to manage website content and user accounts. An authenticated attacker with low-level privileges can exploit a parameter confusion flaw to overwrite any user's credentials, including administrator accounts, leading to complete site takeover and unauthorized access to all managed content and administrative functions.
Technical details
A privilege escalation vulnerability exists in the UsersController's updated_ajax endpoint due to parameter confusion between the authorization filter and the action body. The vulnerability is an insecure direct object reference (IDOR) where the authorization filter checks params[:id] against the current user's ID, but the controller action uses params[:user_id] to load and mutate the target user record. An authenticated attacker can send a PATCH request setting params[:id] to their own user ID (passing authorization) while setting params[:user_id] to a victim's ID, allowing credential overwrite including admin passwords. No authentication bypass is required—the attacker must already be authenticated. Patches are available in the repository after the vulnerability fix commit.
Affected products
- Owen2345 CamaleonCMS 2.9.2 and earlier
Timeline
- 2026-08-11: disclosed
- patched: Fix available in repository commit 26345034523a505cb01615509b7f0a665e89ae3e