CVE-2025-8117CWE-909

Account Takeover via Reset Password Functionality in PAD CMS

High · published September 30, 2025

CVSS v4.0
8.7
EPSS
0%
Percentile
19.1
In the wild
Unconfirmed
What it is

PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This issue affects all 3 templates: www, bip and www+bip.

This product is End-Of-Life and producent will not publish patches for this vulnerability.

The record
Technical detail
CVSS v4.0
8.7 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS
0.00271 · 19.1th percentile
Weakness
CWE-909 · Missing Initialization of Resource
Published
2025-09-30T10:04Z
EPSS history
Timeline
  • 30 SEP 10:04Z
    Account Takeover via Reset Password Functionality in PAD CMS
    cvelistv5