CVE-2025-2304 describes a privilege escalation vulnerability in Camaleon CMS due to improper parameter filtering in the 'updated_ajax' method of the UsersController. The use of the 'permit!' method allows all parameters to be accepted without restriction, enabling attackers to perform mass assignment and potentially modify sensitive user attributes, such as roles or permissions, during password change operations.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
16 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (5 hidden).
This repository is a small standalone Python proof-of-concept exploit for CVE-2025-2304 affecting Camaleon CMS. It contains two files: the main exploit script (CVE-2025-2304.py) and a README with usage instructions. The exploit is not part of a larger framework. The script uses requests, argparse, urllib.parse, and BeautifulSoup. Its workflow is: normalize the supplied target host, request /admin/login to scrape a CSRF token from a meta tag, authenticate with provided username and password, request /admin/profile/edit to extract the current authenticated user's numeric ID from the user[id] form field, then send a crafted POST request to /admin/users/{user_id}/updated_ajax with _method=patch and password[role]=admin. Finally, it requests /admin/dashboard and checks for the string "Administrator" to confirm success. Primary capability: authenticated privilege escalation from a lower-privileged Camaleon CMS account to administrator via mass assignment in the user update flow. This is a web attack vector and requires valid credentials plus a vulnerable target instance. The exploit does not deliver code execution or a shell; it changes application authorization state. The implementation is operational but basic: endpoints and logic are hardcoded, transport is forced to HTTP for subsequent requests even if the input target was normalized with https initially, and exception handling is broad/minimal. Despite those limitations, the code clearly performs exploitation rather than mere detection.
This repository is a small, focused proof-of-concept exploit for CVE-2025-2304 affecting Camaleon CMS 2.9.0. It contains two files: a Python exploit script and a README with usage instructions. The Python script uses the requests library to authenticate to the target web application, scrape CSRF tokens from HTML, and send an authenticated POST request to the vulnerable endpoint /admin/users/{user_id}/updated_ajax. The exploit abuses mass assignment by including password[role]=admin in the password update request, thereby elevating the specified user to administrator while also setting or reusing the account password. After exploitation, it re-authenticates with the updated credentials and attempts to confirm success by requesting /admin/users. The exploit is operational rather than a mere detector because it performs the full attack chain and modifies target state. It is not part of a larger exploitation framework. The repository structure is minimal and purpose-built: README.md documents the vulnerability, prerequisites, and command-line usage; CVE-2025-2304-POC.py implements login, CSRF extraction, privilege escalation, and verification logic.
This repository is a small standalone Python proof-of-concept exploit for CVE-2025-2304, a mass assignment privilege escalation flaw in Camaleon CMS versions prior to 2.9.1. The repo contains only two files: a README with vulnerability explanation, usage guidance, and references; and a single executable Python script, exploit_cve_2025_2304_en.py, which is the main entry point. The exploit is an authenticated web attack, not an RCE. Its purpose is to elevate an existing low-privileged Camaleon CMS user to administrator by abusing the vulnerable password update flow. The script first prompts the operator for a base URL, attacker-controlled user ID, authenticated _cms_session cookie, and optional new password. It then requests the user edit page at /admin/users/{user_id}/edit to scrape the Rails authenticity_token from the password form identified by id 'profie-form-ajax-password'. After obtaining the CSRF token, it sends a POST request to /admin/users/{user_id}/updated_ajax with form-encoded parameters including password[role]=admin, password[id]=<user_id>, password fields, and _method=patch. This leverages the application's unsafe use of permit! on password parameters, allowing role assignment. Capabilities include: automated CSRF token retrieval, authenticated session reuse via supplied cookie, construction of the mass-assignment payload, submission of the forged AJAX request, and basic response analysis for success indicators in JSON or HTML. The script disables TLS verification, supports redirects, and uses simple heuristics to mark likely success when the server returns 200/302 or JSON status values such as ok/success. There is no framework dependency beyond Python requests, no modular payload system, and no persistence or post-exploitation logic beyond changing the password and role. Because it contains a working hardcoded exploit flow with a fixed privilege-escalation payload, it is best classified as OPERATIONAL rather than a mere detection script or README-only PoC.
This repository is a small standalone Python PoC for CVE-2025-2304 affecting Camaleon CMS. The repo contains one substantive code file (cve-2025-2304.py), a README, dependency list, license, and gitignore. The exploit is not part of a larger framework. The Python script uses requests and BeautifulSoup to automate an authenticated web attack against Camaleon CMS. Its workflow is: print banner, authenticate to /admin/login using supplied credentials, fetch CSRF tokens from HTML, query /admin/profile/edit to detect the CMS version and extract the current user ID/username/role, then attempt privilege escalation through mass assignment by submitting crafted user-update data. The README explicitly identifies the vulnerable endpoint as /admin/users/{id}/updated_ajax and explains that the flaw stems from unsafe Rails parameter handling (permit!). Capabilities described in the code/README include: safe testing with password preservation, a no-password-field mode, multiple payload/injection attempts, verbose request logging, proxy support, version detection, and an optional destructive admin takeover/password reset test. This makes it more than a pure detector: it actively attempts exploitation and confirms success conditions. Fingerprintable targets/endpoints include the Camaleon admin login and profile pages, the documented vulnerable AJAX user update endpoint, and an optional local proxy endpoint for traffic interception. No hardcoded victim IPs or domains are embedded; the target base URL is supplied by the operator. Overall, the repository’s purpose is to provide an operational authenticated privilege-escalation PoC for vulnerable Camaleon CMS deployments, allowing a low-privileged user to become an administrator by injecting unauthorized role fields into profile/password update requests.
Repository contains a single Python PoC exploit (CVE-2025-2304.py) and a README. The exploit targets Camaleon CMS versions < 2.9.1 and performs an authenticated privilege escalation via mass assignment in the UsersController updated_ajax endpoint, which uses params.require(:password).permit!. Code flow: - Creates a requests.Session (TLS verification disabled) and logs in at /admin/login using authenticity_token extracted from the login page. - Requests /admin/profile/edit to extract CSRF token and parse the current user’s ID (regex for /admin/users/(\d+)) and role (selected option in select[name="user[role]"]). - If not already admin, sends a crafted form-encoded request to /admin/users/{user_id}/updated_ajax using _method=patch and includes password[role]=admin alongside password change fields. Headers include X-CSRF-Token and X-Requested-With. - Re-queries /admin/profile/edit to verify the role changed to admin and prints the admin login URL. Primary capability: privilege escalation (role change to admin) for an authenticated user; no RCE, shell, or persistence mechanisms are included. The repository is not part of a larger framework and is best characterized as a focused network-based PoC.
Repository contains a single Python exploit script (exp.py) plus a README. The exploit targets Camaleon CMS (claimed CVE-2025-2304) and performs an authenticated privilege escalation via parameter tampering on the profile password-change workflow. Structure & flow (exp.py): 1) Takes arguments: base_url, username, password. 2) GETs /admin/login, parses an authenticity_token (CSRF). 3) POSTs credentials to /admin/login using a requests session (cookie-based auth). 4) GETs /admin/profile/edit, parses footer#main-footer div.pull-right to extract a version string; exits if version >= 2.9.1 (string-compare based, which is potentially unreliable). 5) Locates a password-change form by id "profie-form-ajax-password" (note the apparent typo), extracts authenticity_token. 6) Submits to the form action URL with form data including _method=patch and password[role]=admin, attempting to elevate the logged-in user to admin while setting password/password_confirmation. Key capability: authenticated role escalation to admin by injecting/overposting the role field in the password update request. No reverse shell or command execution payload is included; the outcome is privilege elevation within the web application.
Repository contains a single Python exploit script plus README and requirements. The exploit targets CVE-2025-2304 in Camaleon CMS 2.9.0, described as a critical mass-assignment flaw in UsersController#updated_ajax where Rails strong parameters are bypassed via permit!, allowing attacker-controlled parameters (notably role) to be updated. Structure & purpose: - README.md: Explains the vulnerability, affected version, attack flow, example payload, and usage. - camaleon_cms_privilege_escalation.py: Standalone Python tool using requests.Session to (1) fetch /admin/login and scrape a CSRF token (csrf-token meta tag or authenticity_token input), (2) authenticate to /admin/login with user[username]/user[password], (3) POST to /admin/users/5/updated_ajax with form parameters password[role]=admin plus password/password_confirmation and _method=patch to trigger role escalation, and (4) verify by requesting /admin/dashboard. - requirements.txt: Pins requests==2.32.5. Exploit capabilities: - Authenticated privilege escalation from a normal user to administrator by abusing mass assignment. - Password change for the compromised account (new password optional; defaults to current password). - Basic success heuristics: checks JSON {success:true} / status==success or HTTP 200, then attempts to load the admin dashboard. Notable implementation details/limitations: - The target user ID is hardcoded to 5 in the vulnerable endpoint path; real deployments may require changing this to the attacker’s actual user ID. - No automatic user-ID discovery; relies on operator knowledge/assumption. - Network-only attack requiring valid credentials; no RCE payload included—impact is administrative takeover within the CMS.
Repository contains a single Python exploit script (exploit.py) and a short README. The exploit targets CVE-2025-2304 in Camaleon CMS, described as an unsafe mass-assignment issue (permit! in UsersController#updated_ajax) that allows unfiltered parameters. Exploit flow (exploit.py): 1) Normalizes the provided --url into base_url and builds /admin/login. 2) Uses requests.Session() to GET the login page and parses the Rails authenticity_token from an <input name="authenticity_token">. 3) POSTs credentials (user[username], user[password]) to /admin/login to establish an authenticated session. 4) GETs /admin/profile/edit, parses CSRF token from <meta name="csrf-token">, and extracts the password AJAX update endpoint from the form with id "profie-form-ajax-password". 5) Sends a POST to that extracted endpoint with _method=patch and includes password[role]=admin alongside password fields, attempting to mass-assign the role attribute. 6) Reports success if HTTP 200 is returned and instructs the operator to re-login to observe elevated privileges. No reverse shell or command execution is implemented; the primary capability is authenticated privilege escalation to admin by manipulating HTTP parameters.
Repository contains a single Python PoC exploit (exploit.py) and a minimal README referencing CVE-2025-2304. Exploit flow (requests.Session, TLS verification disabled): 1) GET /admin/login and regex-extract authenticity_token (CSRF) from the login form. 2) POST /admin/login with user[username], user[password], and authenticity_token to authenticate; success is inferred by presence of 'dashboard' or 'logout' in the response body. 3) GET /admin/profile/edit and regex-extract (a) the numeric user_id from a URL matching /admin/users/(\d+)/updated_ajax embedded in the page, and (b) a second CSRF token associated with the AJAX password form. 4) POST /admin/users/{user_id}/updated_ajax with headers typical of an XMLHttpRequest (X-Requested-With, X-CSRF-Token, Origin, Referer) and form data including _method=patch, authenticity_token, password fields, and critically password[role]=admin. Primary capability: authenticated privilege escalation to admin by abusing a vulnerable profile/password update mechanism that improperly allows role modification through nested password parameters. No reverse shell or command execution payload is included; the outcome is an authorization/role change for the logged-in user.
Repository contains a single Python PoC (exploit.py) plus a README describing an authenticated privilege escalation in Camaleon CMS 2.9.0 (CVE-2025-2304 / Tenable TRA-2025-09). The exploit logs in to /admin/login using a CSRF authenticity_token scraped from the login form, then fetches /admin/profile/edit to extract the Rails meta csrf-token, the current user_id, and the currently selected role. It then abuses insecure mass-assignment in /admin/users/{user_id}/updated_ajax by sending a PATCH override with password[role]=admin (along with password/password_confirmation) and CSRF token in both body and X-CSRF-Token header, resulting in role escalation to admin. After escalation it re-requests /admin/profile/edit to verify the role change. Optional functionality (-e) scrapes S3 configuration values from /admin/settings/site by regexing HTML input values for access key, secret key, and endpoint. Optional cleanup (-r) repeats the updated_ajax request to set password[role] back to the original role captured earlier. Overall purpose: demonstrate authenticated role escalation via Rails permit! misuse and optionally demonstrate post-escalation sensitive configuration exposure.
Repository purpose: a Python proof-of-concept for CVE-2025-2304, a Camaleon CMS (<2.8.1) authenticated privilege escalation via mass assignment in the Rails user update AJAX endpoint. Structure: - README.md: Describes the vulnerability (mass assignment through password[...] scope), targeted endpoint (/admin/users/:id/updated_ajax), and intended exploit flow (login -> profile edit token/id scrape -> PATCH-over-POST escalation). - main.py: Implements the flow using requests.Session and BeautifulSoup to scrape authenticity_token and user[id]. It constructs the exploit request with headers (X-CSRF-Token, X-Requested-With, Referer, Origin) and a form payload including _method=patch and password[role]=admin. - requirements.txt: requests + beautifulsoup4 and dependencies. Notable implementation detail: main.py currently prints "Sending exploit" but does not actually send the final exploit HTTP request (no session.post/patch call after building exploit_url/headers/exploit_payload). As written, it is a functional scaffold/partial PoC rather than a fully executing exploit.
Repository contains a single Python exploit script (exploit.py) and a README describing CVE-2025-2304 in Camaleon CMS (privilege escalation via mass assignment in UsersController#updated_ajax using permit!). The exploit is an authenticated, network-based privilege escalation: it logs into the target at /admin/login, scrapes the CSRF authenticity_token from the login form, then requests /admin/profile/edit to (1) extract the numeric user_id via regex and (2) obtain a csrf-token from a meta tag. It then sends a crafted POST to /admin/users/{user_id}/updated_ajax with headers X-CSRF-Token and X-Requested-With: XMLHttpRequest and form data including _method=patch, password/password_confirmation, and the injected parameter password[role]=admin. On HTTP 200 it reports success, indicating the current user has been promoted to admin. No reverse shell or code execution is included; the primary capability is role escalation for the authenticated account.
Repository contains a single Python exploit script (exp.py) plus a README. The exploit targets CVE-2025-2304 in Camaleon CMS (tested on 2.9.0) and performs an authenticated privilege escalation to admin. Core flow in exp.py: 1) Creates a requests.Session with browser-like headers. 2) GETs /admin/login and parses an authenticity_token/CSRF token from the login form. 3) POSTs credentials to /admin/login; checks for login failure by presence of login text and lack of redirect. 4) GETs /admin/profile/edit; optionally parses the footer (#main-footer div.pull-right) to extract a version string and aborts if version >= 2.9.1 (string-compare based check). 5) Locates the password change form (id="profie-form-ajax-password"), extracts authenticity_token, and submits a crafted update request to the form’s action URL. 6) The crafted request includes _method=patch and sets password[role]=admin along with password/password_confirmation, resulting in role escalation if the backend improperly permits mass-assignment/role updates. Notable observables/fingerprintable targets are the Camaleon admin endpoints (/admin/login, /admin/profile/edit) and the derived password-update endpoint from the form action. No hardcoded external C2, IPs, or domains are present; the only network target is the user-supplied base_url.
Repository contains a single Python exploit script (exploit.py) and documentation (README.md) targeting Camaleon CMS versions < 2.9.1. The exploit performs an authenticated, network-based privilege escalation via a mass assignment flaw in the password update AJAX workflow. Structure & flow: - README.md: describes affected versions, requirements (requests, beautifulsoup4), and usage. - exploit.py: CLI tool that (1) GETs /admin/login to scrape authenticity_token, (2) POSTs credentials to /admin/login, (3) GETs /admin/profile/edit and parses the form with id 'profie-form-ajax-password' to extract its action URL and CSRF token, (4) POSTs to that action with _method=patch and includes password[role]=admin to overwrite the user role, (5) re-GETs /admin/profile/edit to verify the selected role is 'admin', and (6) prints the username/password and the session cookies from the requests.Session for reuse. Notable targeting details: - Hardcoded paths: /admin/login and /admin/profile/edit. - The actual vulnerable password-update endpoint is discovered dynamically from the profile page form action attribute. - No reverse shell or code execution payload; the primary capability is role escalation to admin for the supplied account.
Repository contains a single Python proof-of-concept exploit (exploit.py) plus a README. It targets CVE-2025-2304 in Camaleon CMS versions < 2.9.1, exploiting a mass-assignment flaw in the admin users updated_ajax password update flow. The script: (1) creates a requests.Session with TLS verification disabled, (2) GETs /admin/login to scrape the Rails authenticity_token, (3) POSTs credentials to /admin/login to authenticate, (4) GETs /admin/profile/edit to extract the current user’s numeric ID from a /admin/users/{id}/updated_ajax reference and to scrape the CSRF token for the AJAX password form, then (5) POSTs to /admin/users/{id}/updated_ajax with _method=patch and password fields plus the injected parameter password[role]=admin. On HTTP 200 it reports success and instructs the operator to log out and back in to obtain admin privileges. No reverse shell or command execution is included; the sole capability is privilege escalation of the authenticated account.
Repository purpose: a Python 3 proof-of-concept exploit for CVE-2025-2304 affecting Camaleon CMS, demonstrating authenticated privilege escalation via a Rails mass-assignment flaw (permit! in UsersController#updated_ajax). The tool logs in with existing credentials, extracts CSRF tokens, checks the CMS version from the admin profile page, determines the current user’s ID/role, and then attempts multiple mass-assignment payload variants to set the user role to admin while optionally preserving the password. It also includes a safer mode that omits password fields (--no-password-field) and an optional destructive “admin takeover” path that attempts an admin password reset unless --skip-admin-test is used. Repository structure: - README.md: detailed vulnerability explanation, affected versions (<2.9.1), usage examples, and references. - cve-2025-2304.py: main exploit script (entry point) implementing login, CSRF extraction, version detection, user info extraction, and exploitation routines (mass assignment, no-password variant, optional admin reset). - requirements.txt: requests + BeautifulSoup dependencies. - LICENSE/.gitignore: standard project metadata. Notable targeting/IOCs: the exploit interacts with Camaleon CMS admin endpoints (/admin/login, /admin/profile/edit) and the vulnerable updated_ajax user update route (/admin/users/{id}/updated_ajax as documented). It supports an operator-supplied HTTP proxy (commonly http://127.0.0.1:8080) for inspection.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.