CVE-2025-1107 - CERT CVE
ID CVE-2025-1107
Sažetak Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker must create a specific POST request and send it to the endpoint ‘/public/cgi/Gateway.php’.
Reference
CVSS
Base: 9.9
Impact: 5.3
Exploitability:3.9
Pristup
VektorSloženostAutentikacija
NETWORK LOW NONE
Impact
PovjerljivostCjelovitostDostupnost
LOW HIGH LOW
CVSS vektor CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L
Zadnje važnije ažuriranje 07-02-2025 - 14:15
Objavljeno 07-02-2025 - 14:15