Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fx82-rmfc-9cqg

Опубликовано: 30 сент. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This issue affects all 3 templates: www, bip and www+bip.

This product is End-Of-Life and producent will not publish patches for this vulnerability.

PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This issue affects all 3 templates: www, bip and www+bip.

This product is End-Of-Life and producent will not publish patches for this vulnerability.

EPSS

Процентиль: 16%
0.00053
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-909

Связанные уязвимости

CVSS3: 7.5
nvd
4 месяца назад

PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This issue affects all 3 templates: www, bip and www+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.

EPSS

Процентиль: 16%
0.00053
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-909