A vulnerability was found in Odyssey CMS up to 10.34. It has been classified as problematic. Affected is an unknown function of the file /modules/odyssey_contact_form/odyssey_contact_form.php of the component reCAPTCHA Handler. The manipulation of the argument g-recaptcha-response leads to key management error. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
History

Tue, 25 Mar 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Odysseyautomation
Odysseyautomation odyssey Cms
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:odysseyautomation:odyssey_cms:*:*:*:*:*:*:*:*
Vendors & Products Odysseyautomation
Odysseyautomation odyssey Cms

Wed, 12 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Mar 2025 01:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in Odyssey CMS up to 10.34. It has been classified as problematic. Affected is an unknown function of the file /modules/odyssey_contact_form/odyssey_contact_form.php of the component reCAPTCHA Handler. The manipulation of the argument g-recaptcha-response leads to key management error. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title Odyssey CMS reCAPTCHA odyssey_contact_form.php key management
Weaknesses CWE-320
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:P/I:N/A:N'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-03-12T14:56:55.846Z

Reserved: 2025-03-11T15:18:30.501Z

Link: CVE-2025-2220

cve-icon Vulnrichment

Updated: 2025-03-12T14:56:51.284Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-12T02:15:19.300

Modified: 2025-03-25T17:15:07.350

Link: CVE-2025-2220

cve-icon Redhat

No data.