CVE-2025-1107CRITICAL 9.9EPSS p29.9%
CVE-2025-1107CVE-2025-1107
Description
Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker to change another user's password without knowing their current password. To exploit the vulnerability, the attacker must create a specific POST request and send it to the endpoint ‘/public/cgi/Gateway.php’.
Scoring
| CVSS 3.1 | 9.9 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L |
| EPSS | 0.38% probability of exploitation · percentile 29.9% · 2026-06-19T12:03:05Z |
| Published | 2025-02-07 |
| Last modified | 2026-04-15 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Unverified Password Changecwe-620 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.