PT-2026-102448 · Owen2345 · Camaleon Cms
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
owen2345 Camaleon CMS versions prior to 2.9.3
Description
A flaw in the Media Crop Handler component allows for a remote authorization bypass. The issue exists within the
crop() function located in the app/controllers/camaleon cms/admin/media controller.rb file, where manipulation of the saved avatar argument enables the bypass.Recommendations
Upgrade to version 2.9.3.
Exploit
Fix
IDOR
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Camaleon Cms