Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker must create a specific POST request and send it to the endpoint ‘/public/cgi/Gateway.php’.
Metrics
Affected Vendors & Products
References
History
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Feb 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker must create a specific POST request and send it to the endpoint ‘/public/cgi/Gateway.php’. | |
| Title | Unverified password change vulnerability in Janto | |
| Weaknesses | CWE-620 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-02-07T13:38:40.967Z
Updated: 2025-02-12T20:51:40.689Z
Reserved: 2025-02-07T12:01:26.834Z
Link: CVE-2025-1107
Updated: 2025-02-12T20:46:09.587Z
Status : Received
Published: 2025-02-07T14:15:48.343
Modified: 2025-02-07T14:15:48.343
Link: CVE-2025-1107
No data.