Cross-Site Request Forgery in PAD CMS from XyloTech
CVE-2025-8119

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 September 2025

What is CVE-2025-8119?

The PAD CMS product from XyloTech is compromised by a Cross-Site Request Forgery vulnerability, notably in its password reset feature. Attackers can exploit this flaw by crafting a malicious website. When a victim accesses this site, an unsolicited POST request is sent to PAD CMS, enabling the attacker to change the victim's password without consent. This vulnerability impacts all configurations of PAD CMS, including the www, bip, and www+bip templates. As the product is no longer supported, no patches will be released to fix this critical issue.

Affected Version(s)

PAD CMS 0 <= 1.2.1

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CERT.PL
.