Vulnerability record · CVE-2018-7662 · published 4 March 2018
CVE-2018-7662: CouchCMS path disclosure via direct PHP file requests
Couchcms · Couch
CouchCMS through 2.0 exposes the full server filesystem path when an attacker directly requests includes/mysql2i/mysql2i.func.php or addons/phpmailer/phpmailer.php. The flaw is a CWE-200 information exposure that leaks installation paths, which aids reconnaissance for follow-on attacks. It is a low-severity disclosure rather than code execution or data theft.
Description
Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmailer/phpmailer.php.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Automated analysis
medium priorityThe flaw only leaks path information, but it is remotely reachable without authentication and has high EPSS with public exploit references.
What it is
CouchCMS through 2.0 exposes the full server filesystem path when an attacker directly requests includes/mysql2i/mysql2i.func.php or addons/phpmailer/phpmailer.php. The flaw is a CWE-200 information exposure that leaks installation paths, which aids reconnaissance for follow-on attacks. It is a low-severity disclosure rather than code execution or data theft.
Impact
An attacker learns the absolute filesystem path of the CouchCMS installation. That path knowledge can support later attacks such as local file inclusion or path-based targeting, but no direct compromise is gained.
Attack surface
Reachable remotely over HTTP by requesting the two PHP files directly; no authentication and no user interaction are required per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is 0.47085 (98.8th percentile) and both references are tagged Exploit, indicating public exploit detail exists.
What to do
- Upgrade CouchCMS past 2.0 to a release that fixes the path disclosure.
- If upgrade is not possible, block direct HTTP access to includes/mysql2i/mysql2i.func.php and addons/phpmailer/phpmailer.php at the web server or WAF.
- Disable PHP error and path output in production and ensure these library files are not web-accessible.
- Review web server logs for direct requests to these paths to identify scanning activity.
Detection
- Alert on HTTP requests to /includes/mysql2i/mysql2i.func.php or /addons/phpmailer/phpmailer.php.
- Search web logs for responses containing absolute filesystem paths from these endpoints.
- Monitor for scanning patterns enumerating CouchCMS library and addon paths.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/CouchCMS/CouchCMS/issues/46 | ExploitIssue TrackingThird Party Advisory |
| https://github.com/CouchCMS/CouchCMS/issues/46 | ExploitIssue TrackingThird Party Advisory |
Track CVE-2018-7662 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-7662), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.