
Non-destructive Go verifier that checks whether a Camaleon CMS instance applies the authorization fix for CVE-2026-102261 in the media crop endpoint.
This project contains a non-destructive checker to confirm whether an authorized instance of Camaleon CMS enforces the authorization introduced in version 2.9.3.
The issue affects POST /admin/media/crop in Camaleon CMS up to 2.9.2. A user with :manage, :media, but without :manage, :users, could supply another user's ID in saved_avatar and achieve an avatar write outside their authorized object. The fix requires :manage, :users for any target other than the user themselves.
The checker sends a single authenticated POST with:
saved_avatar from a disposable account different from the authenticated account;cp_img_path.In the fixed version, authorization occurs before any file processing and the application responds with a redirect (typically 302). In an older version, the request is not denied at that stage and the result is only INCONCLUSIVE: this program does not send an image, does not read data, and does not attempt to modify any avatar.
Create two test accounts on the same site:
:manage, :media, but without :manage, :users;Obtain the session cookie of the first account and run:
go test ./...
go run . \
--i-own-this-lab \
--url http://127.0.0.1:3000 \
--cookie '_session_id=COLOQUE_A_SESSAO_DE_TESTE_AQUI' \
--nonself-user-id 42
PROTECTED means the endpoint denied the operation before processing the image path. INCONCLUSIVE calls for validating the installed version and updating; it is not confirmation of exploitation.
Update to Camaleon CMS 2.9.3 or later. The patch is c143e145caa600947e70a240e87f2fed889149d3.