Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-67004

Опубликовано: 09 янв. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly. NOTE: A community member states that this is not a CouchCMS vulnerability and that if /<file> is accessible it is a web-server configuration issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:couchcms:couchcms:2.4:*:*:*:*:*:*:*

EPSS

Процентиль: 18%
0.00057
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
github
29 дней назад

An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly.

EPSS

Процентиль: 18%
0.00057
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22