Unauthenticated Password Change Vulnerability in Janto Versions Prior to r12
An unverified password change vulnerability exists in Janto versions before r12. This security issue allows an unauthenticated attacker to modify another user's password without knowing their current password. The vulnerability can be triggered by crafting a specific POST request directed to the '/public/cgi/Gateway.php' endpoint. An attacker could potentially change passwords for any user in the system by sending the maliciously constructed request.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
impronta janto |