CVE Vulnerabilities

CVE-2025-8117

Missing Initialization of Resource

Published: Sep 30, 2025 | Modified: Nov 26, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This issue affects all 3 templates: www, bip and www+bip.

This product is End-Of-Life and producent will not publish patches for this vulnerability.

Weakness

The product does not initialize a critical resource.

Affected Software

Name Vendor Start Version End Version
Pad_cms Widzialni * 1.2.1 (including)

Potential Mitigations

References