CVE-2025-8120 is a critical Remote Code Execution (RCE) vulnerability affecting all templates of the widzialni PAD CMS, a product that is End-of-Life. An unauthenticated remote attacker can exploit a flaw in the upload photo functionality, allowing them to upload and execute arbitrary files due to client-controlled permission checks. This vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a severe risk with network-based exploitation, low attack complexity, and no user interaction required, leading to complete compromise of confidentiality, integrity, and availability. Its FAUCET Risk Score is 95/100, highlighting its significant danger. While there is no evidence of active exploitation, nor publicly available exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community discussion, with one mention indicating awareness of the critical RCE flaw. Given the product's EOL status, no patches will be released, necessitating immediate mitigation actions such as disabling the upload functionality and network segmentation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2.1CPE matchmatch criteria | cpe:2.3:a:widzialni:pad_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.