CVE-2025-7063: Remote Code Execution via Unrestricted File Upload in PAD CMS
Due to client-controlled permission check parameter, PAD CMS's file upload functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can then be executed leading to Remote Code Execution. This issue affects all 3 templates: www, bip and ww+bip.
This product is End-Of-Life and producent will not publish patches for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7063?
CVE-2025-7063 is rated as critical due to its potential to allow unauthenticated remote code execution.
How do I fix CVE-2025-7063?
To fix CVE-2025-7063, you should implement stricter controls on the file upload functionality to validate file types and restrict uploads.
Who is affected by CVE-2025-7063?
CVE-2025-7063 affects all versions of PAD CMS that utilize the vulnerable file upload functionality.
What are the potential consequences of CVE-2025-7063?
The potential consequences of CVE-2025-7063 include unauthorized file uploads and remote code execution leading to system compromise.
How can an attacker exploit CVE-2025-7063?
An attacker can exploit CVE-2025-7063 by using client-controlled parameters to bypass permission checks and upload malicious files.