PT-2025-25544 · Unknown · Mojolicious::Plugin::Captchapng

CVE-2025-40916

·

Published

2025-06-16

·

Updated

2025-06-16

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mojolicious::Plugin::CaptchaPNG version 1.05
Description The issue concerns the use of a weak random number source for generating the captcha in Mojolicious::Plugin::CaptchaPNG for Perl. Specifically, version 1.05 utilizes the built-in rand() function to generate both the captcha text and image noise, which is insecure.
Recommendations For Mojolicious::Plugin::CaptchaPNG version 1.05, consider updating to a newer version that addresses the weak random number source issue. As a temporary workaround, consider disabling the use of the rand() function for generating captcha text and image noise until a patch is available. Restrict access to the captcha generation functionality to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-40916

Affected Products

Mojolicious::Plugin::Captchapng