CVE-2025-1107
CVE-2025-1107
Título es
CVE-2025-1107
Vie, 07/02/2025 – 14:15
Tipo
CWE-620
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-1107
Descripción en
Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker must create a specific POST request and send it to the endpoint ‘/public/cgi/Gateway.php’.
07/02/2025
07/02/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
Gravedad 3.1 (CVSS 3.1 Base Score)
9.90
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
CRITICAL
Referencias
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-janto
Enviar en el boletín
Off