CVE-2025-1108
CVSS 3.1 Score 8.6 of 10 (high)
Details
Published Feb 7, 2025
CWE ID 345
Summary
CVE-2025-1108 is a vulnerability affecting versions prior to r12 of Janto email software. It involves insufficient data authenticity verification, enabling unauthenticated attackers to manipulate the content of password reset emails. To exploit this flaw, an attacker must craft a malicious POST request and inject it into the 'Xml' parameter of the '/public/cgi/Gateway.php' endpoint. This vulnerability could potentially lead to serious consequences, including unauthorized account access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share