PAD CMS improperly initializes parameter used for password recovery, which allows to change password for any user that did not use reset…
CERT-PL·CWE-909·Published 2025-09-30