PT-2025-25544 · Unknown · Mojolicious::Plugin::Captchapng

Published

2025-06-16

·

Updated

2025-06-16

·

CVE-2025-40916

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Mojolicious::Plugin::CaptchaPNG version 1.05
Description The issue concerns the use of a weak random number source for generating the captcha in Mojolicious::Plugin::CaptchaPNG for Perl. Specifically, version 1.05 utilizes the built-in rand() function to generate both the captcha text and image noise, which is insecure.
Recommendations For Mojolicious::Plugin::CaptchaPNG version 1.05, consider updating to a newer version that addresses the weak random number source issue. As a temporary workaround, consider disabling the use of the rand() function for generating captcha text and image noise until a patch is available. Restrict access to the captcha generation functionality to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-40916

Affected Products

Mojolicious::Plugin::Captchapng