PAD CMS is vulnerable to Reflected XSS in printing and save to PDF functionality. Malicious attacker can craft special URL, which will result in arbitrary JavaScript execution in victim's browser, when opened. This issue affects all 3 templates: www, bip and www+bip.
This product is End-Of-Life and producent will not publish patches for this vulnerability.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://cert.pl/posts/2025/09/CVE-2025-7063 |
Configurations
No configuration.
History
30 Sep 2025, 11:37
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-09-30 11:37
Updated : 2025-10-02 19:12
NVD link : CVE-2025-8116
Mitre link : CVE-2025-8116
CVE.ORG link : CVE-2025-8116
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
