Spoofing Vulnerability in Raytha CMS Affects Users' Password Security
CVE-2025-69240

7.5HIGH

Key Information:

Vendor

Raytha

Status
Vendor
CVE Published:
16 March 2026

What is CVE-2025-69240?

Raytha CMS contains a vulnerability that allows attackers to manipulate the X-Forwarded-Host or Host headers, redirecting email reset links to a domain controlled by the attacker. When a victim, identified by their email address, clicks the reset link, the browser sends a request that includes a sensitive token to the attacker's domain. This exposes the token and enables the attacker to reset the victim's password, potentially leading to account compromise. Users should upgrade to version 1.4.6 or later to mitigate this risk.

Affected Version(s)

Raytha 0 < 1.4.6

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Daniel Basta
.