MEDIUM
CouchCMS reCAPTCHA config.example.php hard-coded key
Published Dec 22, 2025
6.3
MEDIUMCVSS 4.0
EPSS 0.46%
Description
A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.example.php of the component reCAPTCHA Handler. The manipulation of the argument K_RECAPTCHA_SITE_KEY/K_RECAPTCHA_SECRET_KEY results in use of hard-coded cryptographic key . It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks.
Affected products
-
- Version 2.0StatusaffectedConstraints-
- Version 2.1StatusaffectedConstraints-
- Version 2.2StatusaffectedConstraints-
- Version 2.3StatusaffectedConstraints-
- Version 2.4StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-204679 Advisory
- https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl relatedExploitThird Party Advisory
- https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl#-span--strong-proof-of-concept---strong---span- exploitThird Party Advisory
- https://vuldb.com/?ctiid.337711 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.337711 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.718998 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-204679 | Advisory | |
| https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl | relatedExploitThird Party Advisory | |
| https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl#-span--strong-proof-of-concept---strong---span- | exploitThird Party Advisory | |
| https://vuldb.com/?ctiid.337711 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.337711 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.718998 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Dec 22, 2025
Updated Feb 24, 2026
Reserved Dec 21, 2025
Link CVE-2025-15005
CISA Vulnrichment
Updated Dec 22, 2025
ENISA EUVD
EUVD-2025-204679 Assigner VulDB
Published Dec 22, 2025
Updated Feb 24, 2026
Exploited since n/a
Link EUVD-2025-204679