CVE-2025-8121: Blind SQL Injection in PAD CMS
Improper neutralization of input provided by an authorized user in article positioning functionality allows for Blind SQL Injection attacks. This issue affects all 3 templates: www, bip and ww+bip.
This product is End-Of-Life and producent will not publish patches for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8121?
CVE-2025-8121 is considered a high severity vulnerability due to its potential for Blind SQL Injection attacks.
How does CVE-2025-8121 affect PAD CMS?
CVE-2025-8121 affects all three PAD CMS templates: www, bip, and ww+bip by allowing improper input neutralization.
Can CVE-2025-8121 be exploited by unauthorized users?
No, CVE-2025-8121 requires that the attacker is an authorized user to exploit the Blind SQL Injection vulnerability.
How do I fix CVE-2025-8121?
There is no fix for CVE-2025-8121 as the affected product, PAD CMS, is End-Of-Life and no patches will be released.
What types of attacks can be performed due to CVE-2025-8121?
CVE-2025-8121 allows attackers to perform Blind SQL Injection attacks, compromising the database security.