CVE-2024-46987
Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability accessible via MediaController's download_private_file method allows authenticated users to download any file on the web server Camaleon CMS is running on (depending on the file permissions). This issue may lead to Information Disclosure. This issue has been addressed in release version 2.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
- Affected products
- Camaleon Cms
- Tuzitio Camaleon Cms
- < 2.8.2
- Fix
- Available
- CVSS 3.1
- 7.7 HIGH
- EPSS
- 14.6% (96th percentile)
- Weakness
- CWE-22, CWE-200
- NVD status
- Modified
- Published
- 2024-09-18
CVE-2024-46987 at NVD
21 known exploits for CVE-2024-46987
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2024-46987
CVE-2024-46987
Exploit-for-CVE-2024-46987
CVE-2024-46987
CVE-2024-46987
CVE-2024-46987
HackTheBox-Facts
CVE-2024-46987
CVE-2024-46987
msf-cve-2024-46987
CVE-2026-66748-Camaleon-CMS---Authenticated-RCE-via-select_eval-Custom-Field β Updated!
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Tuzitio Camaleon_Cms
π Camaleon CMS 2.9.0 Path Traversal
Camaleon CMS v2.9.0 - Path Traversal
Exploit for Exposure of Sensitive Information to an Unauthorized Actor in Tuzitio Camaleon_Cms
Exploit for Path Traversal in Tuzitio Camaleon_Cms
Exploit for Path Traversal in Tuzitio Camaleon_Cms
Exploit for Path Traversal in Tuzitio Camaleon_Cms
Exploit for Path Traversal in Tuzitio Camaleon_Cms
Exploit for Path Traversal in Tuzitio Camaleon_Cms
Camaleon CMS Directory Traversal CVE-2024-46987