CVE-2025-1107

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Feb 7, 2025
CWE ID 620

Summary

CVE-2025-1107 is a password change vulnerability affecting versions of Janto prior to r12. This issue permits unauthenticated attackers to alter another user's password undetected, without requiring knowledge of the current password. Exploitation occurs when an attacker sends a crafted POST request to the 'Gateway.php' endpoint ('/public/cgi/Gateway.php'), potentially leading to compromised user accounts.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share