Insufficient Data Authenticity in Janto Affects Email Password Reset Functionality
CVE-2025-1108
8.6HIGH
What is CVE-2025-1108?
A vulnerability exists in Janto that permits unauthenticated attackers to manipulate email content associated with password reset requests. This flaw arises from inadequate verification of data authenticity, which can be exploited by sending a crafted POST request that injects malicious data into the 'Xml' parameter of the '/public/cgi/Gateway.php' endpoint. Attackers leveraging this vulnerability may compromise user accounts by altering reset emails, posing significant risks to user security.
Affected Version(s)
Janto 0