CVE-2025-8119

PAD CMS is vulnerable to Cross-Site Request Forgery in reset password's functionality. Malicious attacker can craft special website, which when visited by the victim, will automatically send a POST request changing currently logged user's password to defined by the attacker value. This issue affects all 3 templates: www, bip and www+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.
References
Link Resource
https://cert.pl/posts/2025/09/CVE-2025-7063 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:widzialni:pad_cms:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:06

Type Values Removed Values Added
Summary
  • (es) PAD CMS es vulnerable a falsificación de petición en sitios cruzados en la funcionalidad de restablecimiento de contraseña. Un atacante malicioso puede crear un sitio web especial que, al ser visitado por la víctima, enviará automáticamente una petición POST cambiando la contraseña del usuario actualmente autenticado al valor definido por el atacante. Este problema afecta a las 3 plantillas: www, bip y www+bip. Este producto está al final de su vida útil y el productor no publicará parches para esta vulnerabilidad.

26 Nov 2025, 14:40

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.3
First Time Widzialni pad Cms
Widzialni
CPE cpe:2.3:a:widzialni:pad_cms:*:*:*:*:*:*:*:*
References () https://cert.pl/posts/2025/09/CVE-2025-7063 - () https://cert.pl/posts/2025/09/CVE-2025-7063 - Third Party Advisory

30 Sep 2025, 11:37

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-30 11:37

Updated : 2026-06-17 10:06


NVD link : CVE-2025-8119

Mitre link : CVE-2025-8119

CVE.ORG link : CVE-2025-8119


JSON object : View

Products Affected

widzialni

  • pad_cms
CWE
CWE-352

Cross-Site Request Forgery (CSRF)