CVE-2025-67004

medium

Description

An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly.

References

https://www.couchcms.com/

https://github.com/CouchCMS/CouchCMS

https://gist.github.com/thepiyushkumarshukla/d01f8004c43692f18c75548f4739955a

Details

Source: Mitre, NVD

Published: 2026-01-09

Updated: 2026-01-12

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.00017