CVE-2025-2220

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 12, 2025
Updated: Mar 25, 2025
CWE ID 320

Summary

CVE-2025-2220 is a newly disclosed vulnerability affecting Odyssey CMS versions up to 10.34. The issue lies in the reCAPTCHA Handler's /modules/odyssey_contact_form/odyssey_contact_form.php file. Manipulation of the g-recaptcha-response argument results in a key management error, which can be exploited with local access. The vulnerability has been made public, and the attack method is known, increasing the threat to affected systems. Despite early disclosure, the vendor has not responded to reports about this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share