SB2025031816 - Privilege escalation in Camaleon CMS
Published: March 18, 2025 Updated: February 13, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2025-2304)
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to use of the dangerous permit! method, which allows all parameters to pass through without any filtering, leading to security restrictions bypass and privilege escalation.
Remediation
Install update from vendor's website.