No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 28 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Jul 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Owen2345
Owen2345 camaleon Cms |
|
| Vendors & Products |
Owen2345
Owen2345 camaleon Cms |
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers can store an attacker-controlled Ruby expression in the field options command parameter, which is evaluated via instance_eval within an ERB view whenever a post edit page is rendered, achieving server-side code execution with web server process privileges. | |
| Title | Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field | |
| Weaknesses | CWE-94 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-28T19:27:14.879Z
Reserved: 2026-07-27T16:27:47.648Z
Link: CVE-2026-66748
Updated: 2026-07-28T19:27:09.949Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-28T18:45:12Z