Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-8117

Опубликовано: 30 сент. 2025
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This issue affects all 3 templates: www, bip and www+bip.

This product is End-Of-Life and producent will not publish patches for this vulnerability.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:widzialni:pad_cms:*:*:*:*:*:*:*:*
Версия до 1.2.1 (включая)

EPSS

Процентиль: 16%
0.00053
Низкий

7.5 High

CVSS3

Дефекты

CWE-909

Связанные уязвимости

CVSS3: 7.5
github
4 месяца назад

PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This issue affects all 3 templates: www, bip and www+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.

EPSS

Процентиль: 16%
0.00053
Низкий

7.5 High

CVSS3

Дефекты

CWE-909