Back to overview

CVE-2025-1107

CRITICAL
9.9
CVSS 3.1
Description
Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker must create a specific POST request and send it to the endpoint ‘/public/cgi/Gateway.php’.

Metadata

CVE ID
CVE-2025-1107
State
PUBLISHED
Assigner
INCIBE
Reserved
2025-02-07 12:01 UTC
Published
2025-02-07 13:38 UTC
Last updated
2025-02-12 20:51 UTC
Primary CWE
CWE-620
CWE-620: Unverified Password Change
Vendor / Product
Impronta / Janto
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Impronta Janto 0 < r12
Weakness (CWE)
CWESourceDescription
CWE-620 cna CWE-620: Unverified Password Change
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
Back to overview