9.9
CVSSv3

CVE-2025-1107

CVSSv4: NA | CVSSv3: 9.9 | CVSSv2: NA | VMScore: 1000 | EPSS: 0.00075 | KEV: Not Included
Published: 07/02/2025 Updated: 07/02/2025

Vulnerability Summary

Unauthenticated Password Change Vulnerability in Janto Versions Prior to r12

An unverified password change vulnerability exists in Janto versions before r12. This security issue allows an unauthenticated attacker to modify another user's password without knowing their current password. The vulnerability can be triggered by crafting a specific POST request directed to the '/public/cgi/Gateway.php' endpoint. An attacker could potentially change passwords for any user in the system by sending the maliciously constructed request.

Solution

With the implemented patches by the Impronta team, the detected vulnerabilities have been fixed. All customers using this product in SaaS mode have been upgraded to version r12 which fixes these issues.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

impronta janto