Remote Code Execution Vulnerability in PAD CMS by PAD Technologies
CVE-2025-8120

10CRITICAL

Key Information:

Status
Vendor
CVE Published:
30 September 2025

What is CVE-2025-8120?

The PAD CMS platform features a severe vulnerability stemming from a client-controlled permission check in its file upload functionality. This flaw permits unauthenticated remote attackers to upload arbitrary files of any type and extension, bypassing normal restrictions. If exploited, this can lead to remote code execution, posing significant security risks. The vulnerability impacts all three templates of PAD CMS: www, bip, and ww+bip. Note that this product is no longer supported and the vendor will not provide patches for this issue.

Affected Version(s)

PAD CMS 0 <= 1.2.1

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CERT.PL
.
CVE-2025-8120 : Remote Code Execution Vulnerability in PAD CMS by PAD Technologies