CVE-2025-15005

A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.example.php of the component reCAPTCHA Handler. The manipulation of the argument K_RECAPTCHA_SITE_KEY/K_RECAPTCHA_SECRET_KEY results in use of hard-coded cryptographic key . It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be exploited.
References
Link Resource
https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl Exploit Third Party Advisory
https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl#-span--strong-proof-of-concept---strong---span- Exploit Third Party Advisory
https://vuldb.com/?ctiid.337711 Permissions Required VDB Entry
https://vuldb.com/?id.337711 Third Party Advisory VDB Entry
https://vuldb.com/?submit.718998 Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:couchcms:couchcms:*:*:*:*:*:*:*:*

History

31 Dec 2025, 15:50

Type Values Removed Values Added
References () https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl - () https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl - Exploit, Third Party Advisory
References () https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl#-span--strong-proof-of-concept---strong---span- - () https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl#-span--strong-proof-of-concept---strong---span- - Exploit, Third Party Advisory
References () https://vuldb.com/?ctiid.337711 - () https://vuldb.com/?ctiid.337711 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.337711 - () https://vuldb.com/?id.337711 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.718998 - () https://vuldb.com/?submit.718998 - Third Party Advisory, VDB Entry
First Time Couchcms
Couchcms couchcms
CPE cpe:2.3:a:couchcms:couchcms:*:*:*:*:*:*:*:*

22 Dec 2025, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-22 01:16

Updated : 2025-12-31 15:50


NVD link : CVE-2025-15005

Mitre link : CVE-2025-15005

CVE.ORG link : CVE-2025-15005


JSON object : View

Products Affected

couchcms

  • couchcms
CWE
CWE-320

Key Management Errors

CWE-321

Use of Hard-coded Cryptographic Key