Impact
CamaleonCMS 2.9.1 contains a server‑side template injection flaw that allows an authenticated administrator to embed ERB tags in the email field of the test_email settings action, which are rendered inside an exception message and executed as Ruby code, enabling the attacker to run arbitrary commands with the Rails process privileges.
Affected Systems
The vulnerability targets CamaleonCMS 2.9.1 where the test_email endpoint is present; administrators with valid credentials can invoke the action.
Risk and Exploitability
The flaw carries a CVSS score of 7.5 and is not listed in the CISA KEV catalog; EPSS data is not available. The likely attack vector requires authenticated access to the admin interface and exploitation occurs when the attacker submits a crafted email parameter that is reflected back in an SMTP exception rendered as an inline ERB template, leading to remote code execution.
OpenCVE Enrichment