An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly.
History

Mon, 12 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 12 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Couchcms
Couchcms couchcms
Vendors & Products Couchcms
Couchcms couchcms

Fri, 09 Jan 2026 17:00:00 +0000

Type Values Removed Values Added
Description An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back. It can Disclosure the source code or any other confidential information if weaponize accordingly.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-01-09T00:00:00.000Z

Updated: 2026-01-12T16:24:24.173Z

Reserved: 2025-12-08T00:00:00.000Z

Link: CVE-2025-67004

cve-icon Vulnrichment

Updated: 2026-01-12T15:35:37.743Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-09T17:15:53.030

Modified: 2026-01-13T14:03:46.203

Link: CVE-2025-67004

cve-icon Redhat

No data.