Beveiligingsadvies

CVE-2025-1108

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-02-07 13:40:09
Laatst bijgewerkt 2025-02-12 20:51:40
Toegewezen door INCIBE
CVSS-score 8.6
Status PUBLISHED

Beschrijving

Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This allows an unauthenticated attacker to modify the content of emails sent to reset the password. To exploit the vulnerability, the attacker must create a POST request by injecting malicious content into the ‘Xml’ parameter on the ‘/public/cgi/Gateway.php’ endpoint.