Home
HIGH: 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:NDefault status
unknown
Any version
affected
Description
PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This issue affects all 3 templates: www, bip and www+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.
Problem types
CWE-909 Missing Initialization of Resource
Product status
Any version
Credits
Mateusz Jurczak (CERT.PL)
References
cert.pl/posts/2025/09/CVE-2025-7063