CVE-2025-24949
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Apr 15, 2025
Updated: Apr 22, 2025
CWE ID 287
Summary
CVE-2025-24949 is a vulnerability affecting JotUrl 2.0, where the password change process contains a bypass mechanism for security requirements. This issue allows an unauthorized user to modify a victim's account password without proper authentication. The flaw poses a significant risk, as it enables unauthorized access to user accounts. Users are advised to upgrade their JotUrl software to a patched version as soon as possible to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.