Insufficient data authenticity vulnerability in Janto
Vulnerability Description
Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This allows an unauthenticated attacker to modify the content of emails sent to reset the password. To exploit the vulnerability, the attacker must create a POST request by injecting malicious content into the ‘Xml’ parameter on the ‘/public/cgi/Gateway.php’ endpoint.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-1108
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Guzmán Fernández Ocaña
Affected Vendor
Impronta
View all reports →