
PoC that demonstrates CVE-2025-2304 mass assignment privilege escalation in Camaleon CMS by injecting a role attribute into the password parameter during user profile updates.
This repository contains a Functional Proof of Concept (PoC) for a Mass Assignment vulnerability in Camaleon CMS (versions prior to 2.8.1). The vulnerability resides in the updated_ajax endpoint of the User Management module, where the application fails to strictly filter sensitive attributes within the password parameter hash.
By injecting a role attribute into the password scope during a profile update, a low-privileged user can overwrite their own permissions to gain admin status.
The vulnerability is rooted in a misconfiguration of Strong Parameters in the Ruby on Rails controller. When the application processes the AJAX update request, it improperly allows the role key to be merged into the user object's attributes:
/admin/users/:id/updated_ajaxpassword[...]password[role]=adminrequests.Session to maintain state across the authentication and exploitation phases.authenticity_token from the DOM and synchronizes it with the X-CSRF-Token header, satisfying Rails' AJAX security requirements./admin/profile/edit page to dynamically resolve the user[id] required for the RESTful endpoint._method=patch override to satisfy the application's routing requirements for resource updates via POST.requestsbeautifulsoup4Install dependencies:
pip install -r requirements.txt
python3 main.py -u <target_url> --user <username> --password <password>
/admin/login): Establishes an authenticated session using user[username]./admin/profile/edit): Extracts the unique user[id] and a fresh authenticity_token./admin/users/:id/updated_ajax): Dispatches the injection payload.The exploit utilizes an application/x-www-form-urlencoded payload structured as follows:
| Parameter | Value | Description |
|---|---|---|
_method | patch | Rails REST method override |
authenticity_token | [Captured] | Synchronized CSRF protection |
password[password] | [NewPassword] | Required for password-scope validation |
password[role] | admin | Malicious Injection |
This tool is for educational purposes and authorized penetration testing only. Unauthorized access to production systems is illegal.