Permissions, Privileges, and Access Controls in Camaleon CMS - CVE-2025-2304
Published: March 18, 2025 / Updated: April 30, 2026
Vulnerability identifier: #VU105805
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-2304
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to use of the dangerous permit! method, which allows all parameters to pass through without any filtering, leading to security restrictions bypass and privilege escalation.
Affected software
Camaleon CMS
How to mitigate CVE-2025-2304
Install updates from vendor's website.
Camaleon CMS - update to 2.9.1
Links to Public Exploits and PoC-codes
- Exploit #12687 - CVE-2025-2304-exploit () (April 30, 2026)
- Exploit #12441 - Camaleon-CMS-Exploits (CVE for Camaleon-CMS-Exploits (For Study and Education)) (February 27, 2026)
- Exploit #12397 - CVE-2025-2304 (February 13, 2026)
- Exploit #12382 - CVE-2025-2304 (February 6, 2026)
- Exploit #12381 - Exploit-for-CVE-2025-2304 (Exploit for CVE-2025-2304) (February 6, 2026)
- Exploit #12378 - CVE-2025-2304 (February 6, 2026)
- Exploit #12377 - CVE-2025-2304 (Exploit for CVE-2025-2304 | Camaleon CMS versions < 2.9.1) (February 6, 2026)
- Exploit #12370 - CVE-2025-2304-POC (February 6, 2026)