← Back to browse · API

CVE-2024-46986

Severity
CRITICAL
CVSS
10.0
EPSS
0.37358
Risk score
53.08
CISA KEV
No
PoC
Yes
Published
2024-09-18
Modified
2025-04-17
First seen
2026-08-07
Aliases
EUVD-2024-2890, GHSA-WMJG-VQHV-Q5P5
Products
owen2345:camaleon-cms < 2.8.2
Sources
github 3b993dca9a45707f59768bff|CVE-2024-46986
euvd EUVD-2024-2890

Description

Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upload method of the MediaController allows authenticated users to write arbitrary files to any location on the web server Camaleon CMS is running on (depending on the permissions of the underlying filesystem). E.g. This can lead to a delayed remote code execution in case an attacker is able to write a Ruby file into the config/initializers/ subfolder of the Ruby on Rails application. This issue has been addressed in release version 2.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.

References