Security Advisory

CVE-2025-1108

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-02-07 13:40:09
Last updated 2025-02-12 20:51:40
Assigner INCIBE
State PUBLISHED

Description

Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This allows an unauthenticated attacker to modify the content of emails sent to reset the password. To exploit the vulnerability, the attacker must create a POST request by injecting malicious content into the ‘Xml’ parameter on the ‘/public/cgi/Gateway.php’ endpoint.