CVE-2025-1108

Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This allows an unauthenticated attacker to modify the content of emails sent to reset the password. To exploit the vulnerability, the attacker must create a POST request by injecting malicious content into the ‘Xml’ parameter on the ‘/public/cgi/Gateway.php’ endpoint.
Configurations

No configuration.

History

07 Feb 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-07 14:15

Updated : 2025-02-07 14:15


NVD link : CVE-2025-1108

Mitre link : CVE-2025-1108

CVE.ORG link : CVE-2025-1108


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity