PAD CMS Unrestricted File Upload Vulnerability Leading to Remote Code Execution
Vulnerability
A vulnerability in PAD CMS's photo upload feature allows unauthenticated remote attackers to upload files of any type and extension without restriction. This unrestricted file upload can be exploited to execute uploaded files, leading to remote code execution. The vulnerability arises from client-controlled permission check parameters and affects all templates: www, bip, and ww+bip. This version of PAD CMS is end-of-life, and no patches will be released.
Impact
Exploitation of this vulnerability allows for remote code execution on the server where PAD CMS is hosted.
Added: Sep 30, 2025, 11:59 AM
Updated: Sep 30, 2025, 11:59 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
10.0exploitability
7.4remediation
0.0relevance
0.6threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
