
Camaleon CMS(< 2.9.1)における重大なマスアサインメントの脆弱性により、認証された低権限ユーザーが管理者権限に昇格できる可能性があります。この欠陥は `updated_ajax` に存在します。
このプロジェクトは、Camaleon CMS v2.9.1以降に影響する権限昇格の脆弱性を実証・分析するためのPythonベースの概念実証エクスプロイトツールです。スクリプトは、対象インスタンスへの認証、アプリケーション状態情報の取得、脆弱なコードパスが存在するかどうかの検証を自動化します。
pip install requests beautifulsoup4
python exploit.py --target <host> --port <port> -u <username> -p <password>
python exploit.py --target example.com --port 80 -u testuser -p Password123
| 引数 | 必須 | 説明 |
|---|---|---|
--target | はい | 対象ドメインまたはIPアドレス (例: example.com) |
--port | はい | 対象サービスのポート。デフォルト: 80 |
-u | はい | Camaleon CMS ユーザー名 |
-p | はい | Camaleon CMS パスワード |
usage: exploit.py [-h] --target TARGET --port PORT -u U -p P
CVE-2025-2304 - Camaleon CMS >2.9.1 Privilege Escalation by Mass Assignment
Exploit Tool - PoC
options:
-h, --help show this help message and exit
--target TARGET Enter the target domain or ip.
Ex: -t example.com
--port PORT Enter target port
-u U Enter Camaleon CMS Username
-p P Enter Camaleon CMS Password
project/ ├── exploit.py └── README.md
このプロジェクトはセキュリティ研究および教育目的で提供されています。使用前に、すべての該当する法律と認可要件の遵守を確認する責任はユーザーにあります。