CVE-2025-8118: Bruteforce Protection Bypass in PAD CMS
PAD CMS implements weak client-side brute-force protection by utilizing two cookies: logincount and logintimeout. Information about attempt count or timeout is not stored on the server, which allows a malicious attacker to bypass this brute-force protection by resetting those cookies. This issue affects all 3 templates: www, bip and www+bip.
This product is End-Of-Life and producent will not publish patches for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8118?
CVE-2025-8118 is classified as a medium severity vulnerability due to weak client-side brute-force protection.
How do I fix CVE-2025-8118?
To fix CVE-2025-8118, implement proper server-side logging and rate limiting for login attempts.
What systems are affected by CVE-2025-8118?
CVE-2025-8118 specifically affects PAD CMS.
What type of vulnerability is CVE-2025-8118?
CVE-2025-8118 is a security vulnerability relating to inadequate brute-force protection.
Can CVE-2025-8118 be exploited remotely?
Yes, CVE-2025-8118 can be exploited remotely by attackers trying to bypass login protections.