CVE Vulnerabilities

CVE-2025-8117

Missing Initialization of Resource

Published: Sep 30, 2025 | Modified: Nov 26, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This issue affects all 3 templates: www, bip and www+bip.

This product is End-Of-Life and producent will not publish patches for this vulnerability.

Weakness

The product does not initialize a critical resource.

Affected Software

NameVendorStart VersionEnd Version
Pad_cmsWidzialni*1.2.1 (including)

Potential Mitigations

References