CVE-2025-15005 Details
Description
A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.example.php of the component reCAPTCHA Handler. The manipulation of the argument K_RECAPTCHA_SITE_KEY/K_RECAPTCHA_SECRET_KEY results in use of hard-coded cryptographic key . It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit has been released to the public and may be used for attacks.
A vulnerability exists in CouchCMS versions through 2.4, specifically within the reCAPTCHA Handler component. The issue arises from hardcoded test keys in the file couch/config.example.php, which always return a successful verification response. This flaw allows for the automation of form submissions protected by reCAPTCHA, such as contact, comment, and registration forms, without actually solving the CAPTCHA. The vulnerability can be exploited remotely, although it requires a certain level of complexity.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl | [email protected] | ExploitThird Party Advisory |
| https://note-hxlab.wetolink.com/share/jNNcrdrNyCvl#-span--strong-proof-of-concept---strong---span- | [email protected] | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.337711 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.337711 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.718998 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-320 | Key Management Errors | [email protected] |
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| couchcms couchcms | <= 2.4 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Feb 24, 2026 | CVE Modified | [email protected] |
| Dec 31, 2025 | Initial Analysis | [email protected] |
| Dec 22, 2025 | New CVE Received | [email protected] |