Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker must create a specific POST request and send it to the endpoint ‘/public/cgi/Gateway.php’.
History

Wed, 12 Feb 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Feb 2025 13:45:00 +0000

Type Values Removed Values Added
Description Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker must create a specific POST request and send it to the endpoint ‘/public/cgi/Gateway.php’.
Title Unverified password change vulnerability in Janto
Weaknesses CWE-620
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-02-12T20:51:40.689Z

Reserved: 2025-02-07T12:01:26.834Z

Link: CVE-2025-1107

cve-icon Vulnrichment

Updated: 2025-02-12T20:46:09.587Z

cve-icon NVD

Status : Received

Published: 2025-02-07T14:15:48.343

Modified: 2025-02-07T14:15:48.343

Link: CVE-2025-1107

cve-icon Redhat

No data.