<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T22:20:11.408645+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-231618</id>
    <title>EUVD-2026-231618</title>
    <updated>2026-10-06T22:20:11.459612+00:00</updated>
    <content>EUVD-2026-231618</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-231618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-46987</id>
    <title>fkie_cve-2024-46987</title>
    <updated>2026-10-06T22:20:11.459656+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability accessible via MediaController's download_private_file method allows authenticated users to download any file on the web server Camaleon CMS is running on (depending on the file permissions). This issue may lead to Information Disclosure. This issue has been addressed in release version 2.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-46987"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cp65-5m9r-vc2c</id>
    <title>GHSA-cp65-5m9r-vc2c — Camaleon CMS vulnerable to arbitrary path traversal (GHSL-2024-183)</title>
    <updated>2026-10-06T22:20:11.459695+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: camaleon_cms</p>
<p>A path traversal vulnerability accessible via MediaController's download_private_file method allows authenticated users to download any file on the web server Camaleon CMS is running on (depending on the file permissions).</p>
<p>In the [download_private_file](https://github.com/owen2345/camaleon-cms/blob/feccb96e542319ed608acd3a16fa5d92f13ede67/app/controllers/camaleon_cms/admin/media_controller.rb#L28) method:
```ruby
def download_private_file
  cama_uploader.enable_private_mode!</p>
<p>file = cama_uploader.fetch_file("private/#{params[:file]}")</p>
<p>send_file file, disposition: 'inline'
end
```
The file parameter is passed to the [fetch_file](https://github.com/owen2345/camaleon-cms/blob/feccb96e542319ed608acd3a16fa5d92f13ede67/app/uploaders/camaleon_cms_local_uploader.rb#L27) method of the CamaleonCmsLocalUploader class (when files are uploaded locally):
```ruby
def fetch_file(file_name)
  raise ActionController::RoutingError, 'File not found' unless file_exists?(file_name)</p>
<p>file_name
end
```
If the file exists it's passed back to the download_private_file method where the file is sent to the user via [send_file](https://github.com/owen2345/camaleon-cms/blob/feccb96e542319ed608acd3a16fa5d92f13ede67/app/controllers/camaleon_cms/admin/media_controller.rb#L33-L34).</p>
<p>Proof of concept
An authenticated user can download the /etc/passwd file by visiting an URL such as:</p>
<p>https://&lt;camaleon-host&gt;/admin/media/download_private_file?file=../../../../../../etc/passwd
Impact
This issue may lead…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cp65-5m9r-vc2c"/>
  </entry>
</feed>
