CVE-2025-8120: Remote Code Execution via Unrestricted File Upload in PAD CMS
Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can then be executed leading to Remote Code Execution.This issue affects all 3 templates: www, bip and ww+bip.
This product is End-Of-Life and producent will not publish patches for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8120?
CVE-2025-8120 is considered a critical vulnerability due to its potential for Remote Code Execution.
How do I fix CVE-2025-8120?
To fix CVE-2025-8120, implement proper server-side validation of file uploads and restrict file types.
What are the impacts of CVE-2025-8120?
The impact of CVE-2025-8120 allows an unauthenticated attacker to upload arbitrary files, leading to potential Remote Code Execution.
Which software versions are affected by CVE-2025-8120?
All versions of PAD CMS are affected by CVE-2025-8120.
Is authentication required to exploit CVE-2025-8120?
No, CVE-2025-8120 can be exploited by unauthenticated attackers.