CVE-2026-66748: Sir, Your Dropdown Is Running Bash: Finding RCE in Camaleon CMS
A select field with Ruby eval support and no sanitization becomes a remote code execution vector in Camaleon CMS, exploitable by any editor-level account.
A select field with Ruby eval support and no sanitization becomes a remote code execution vector in Camaleon CMS, exploitable by any editor-level account.