CVE-2025-1108

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Feb 7, 2025
CWE ID 345

Summary

CVE-2025-1108 is a vulnerability affecting versions prior to r12 of Janto email software. It involves insufficient data authenticity verification, enabling unauthenticated attackers to manipulate the content of password reset emails. To exploit this flaw, an attacker must craft a malicious POST request and inject it into the 'Xml' parameter of the '/public/cgi/Gateway.php' endpoint. This vulnerability could potentially lead to serious consequences, including unauthorized account access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share