CVE-2025-1107

CRITICAL

Janto <r12 - Info Disclosure

Title source: llm
STIX 2.1

Description

Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker must create a specific POST request and send it to the endpoint ‘/public/cgi/Gateway.php’.

Scores

CVSS v3 9.9
EPSS 0.0005
EPSS Percentile 15.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-620
Status published
Products (1)
Impronta/Janto < r12
Published Feb 07, 2025
Tracked Since Feb 18, 2026