CVE-2025-8117: Account Takeover via Reset Password Functionality in PAD CMS
PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This issue affects all 3 templates: www, bip and www+bip.
This product is End-Of-Life and producent will not publish patches for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8117?
CVE-2025-8117 is a high severity vulnerability that allows unauthorized password changes for any user.
How do I fix CVE-2025-8117?
There is no fix available for CVE-2025-8117 as the product is End-Of-Life and the vendor has ceased publishing patches.
What versions of PAD CMS are affected by CVE-2025-8117?
All versions of PAD CMS are affected by CVE-2025-8117, as it impacts all templates: www, bip, and www+bip.
Can users mitigate the risks of CVE-2025-8117?
Users can mitigate the risks of CVE-2025-8117 by discontinuing use of PAD CMS and moving to a supported platform.
Is there any official guidance on CVE-2025-8117?
No official guidance is available for CVE-2025-8117 due to the product being End-Of-Life.