CVE-2025-8117
PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This issue affects all 3 templates: www, bip and www+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-909
- Published
- 2025-09-30
- Last modified
- 2026-03-12
Affected products
- Polska Akademia Dostępności PAD CMS
Weakness type
Related vulnerabilities
- CVE-2026-40687 — In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource,...
- CVE-2025-54410 — Moby's Firewalld reload removes bridge network isolation
- CVE-2025-54388 — Moby's Firewalld reload makes published container ports accessible from remote hosts
- CVE-2024-53845 — AES/CBC Constant IV Vulnerability in ESPTouch v2
- CVE-2024-8178 — Multiple issues in ctl(4) CAM Target Layer
- CVE-2024-32945 — LaTeX post content manipulation via renderer state leak across contexts
- CVE-2022-0175 — A flaw was found in the VirGL virtual OpenGL renderer (virglrenderer). The virgl did not properly...
- CVE-2022-0382 — An information leak flaw was found due to uninitialized memory in the Linux kernel's TIPC protocol...