CVE-2025-1108

Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This allows an unauthenticated attacker to modify the content of emails sent to reset the password. To exploit the vulnerability, the attacker must create a POST request by injecting malicious content into the ‘Xml’ parameter on the ‘/public/cgi/Gateway.php’ endpoint.
Configurations

No configuration.

History

No history.

Information

Published : 2025-02-07 14:15

Updated : 2025-02-07 14:15


NVD link : CVE-2025-1108

Mitre link : CVE-2025-1108

CVE.ORG link : CVE-2025-1108


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity