PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset password functionality. This issue affects all 3 templates: www, bip and www+bip.
This product is End-Of-Life and producent will not publish patches for this vulnerability.
| Software | From | Fixed in |
|---|---|---|
| widzialni / pad_cms | - | 1.2.1.x |