Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
CamaleonCMS 2.9.2 Privilege Escalation via Parameter Confusion in UsersController
Vulnerability Description
CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confusion flaw between the authorization filter and action body in the UsersController. Attackers can send a PATCH request to the updated_ajax endpoint setting params[:id] to their own user ID to pass the self-authorization check while simultaneously setting params[:user_id] to a victim's ID, causing the controller to load and mutate the victim's account, including overwriting administrator passwords to achieve full site takeover.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
Owen Peredo Diaz CamaleonCMS 授权问题漏洞
Vulnerability Description
Owen Peredo Diaz CamaleonCMS是Owen Peredo Diaz个人开发者的一款内容管理系统。 Owen Peredo Diaz CamaleonCMS 2.9.2及之前版本存在授权问题漏洞,该漏洞源于不安全的直接对象引用(IDOR),由于UsersController中授权过滤器与动作体之间的参数混淆,可能导致经过身份验证的低权限攻击者覆盖任意用户凭据(包括管理员密码),实现完全接管站点。
CVSS Information
N/A
Vulnerability Type
N/A