Blind SQL Injection Vulnerability in End-of-Life Product by Vendor
CVE-2025-8122
8.7HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 30 September 2025
What is CVE-2025-8122?
This vulnerability arises from improper neutralization of user input within the article positioning functionality, allowing attackers to exploit it through Blind SQL Injection methods. It is pertinent to note that the affected product is no longer maintained, and the vendor has announced that no patches or updates will be provided, leaving systems vulnerable to potential exploitation.
Affected Version(s)
PAD CMS 0 <= 1.2.1