Spoofing Vulnerability in Raytha CMS Affects Users' Password Security
CVE-2025-69240
7.5HIGH
What is CVE-2025-69240?
Raytha CMS contains a vulnerability that allows attackers to manipulate the X-Forwarded-Host or Host headers, redirecting email reset links to a domain controlled by the attacker. When a victim, identified by their email address, clicks the reset link, the browser sends a request that includes a sensitive token to the attacker's domain. This exposes the token and enables the attacker to reset the victim's password, potentially leading to account compromise. Users should upgrade to version 1.4.6 or later to mitigate this risk.
Affected Version(s)
Raytha 0 < 1.4.6
