A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.example.php of the component reCAPTCHA Handler. The manipulation of the argument K_RECAPTCHA_SITE_KEY/K_RECAPTCHA_SECRET_KEY results in use of hard-coded cryptographic key
. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be exploited.
References
| Link | Resource |
|---|---|
| https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl | Exploit Third Party Advisory |
| https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl#-span--strong-proof-of-concept---strong---span- | Exploit Third Party Advisory |
| https://vuldb.com/?ctiid.337711 | Permissions Required VDB Entry |
| https://vuldb.com/?id.337711 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.718998 | Third Party Advisory VDB Entry |
Configurations
History
31 Dec 2025, 15:50
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl - Exploit, Third Party Advisory | |
| References | () https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl#-span--strong-proof-of-concept---strong---span- - Exploit, Third Party Advisory | |
| References | () https://vuldb.com/?ctiid.337711 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.337711 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.718998 - Third Party Advisory, VDB Entry | |
| First Time |
Couchcms
Couchcms couchcms |
|
| CPE | cpe:2.3:a:couchcms:couchcms:*:*:*:*:*:*:*:* |
22 Dec 2025, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-22 01:16
Updated : 2025-12-31 15:50
NVD link : CVE-2025-15005
Mitre link : CVE-2025-15005
CVE.ORG link : CVE-2025-15005
JSON object : View
Products Affected
couchcms
- couchcms
