CVE-2025-67004

medium

Description

** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly. NOTE: A community member states that this is not a CouchCMS vulnerability and that if /\<file> is accessible it is a web-server configuration issue.

References

https://www.couchcms.com/

https://github.com/CouchCMS/CouchCMS

https://gist.github.com/thepiyushkumarshukla/d01f8004c43692f18c75548f4739955a

Details

Source: Mitre, NVD

Published: 2026-01-09

Updated: 2026-01-23

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00017