Cross-Site Request Forgery in PAD CMS from XyloTech
CVE-2025-8119
Key Information:
- Status
- Vendor
- CVE Published:
- 30 September 2025
What is CVE-2025-8119?
The PAD CMS product from XyloTech is compromised by a Cross-Site Request Forgery vulnerability, notably in its password reset feature. Attackers can exploit this flaw by crafting a malicious website. When a victim accesses this site, an unsolicited POST request is sent to PAD CMS, enabling the attacker to change the victim's password without consent. This vulnerability impacts all configurations of PAD CMS, including the www, bip, and www+bip templates. As the product is no longer supported, no patches will be released to fix this critical issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
PAD CMS 0 <= 1.2.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
