CVE-2024-10332: Janto

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

A Cross-Site Scripting vulnerability has been found in Janto v4.3r11 from Impronta. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the endpoint “/abonados/public/janto/main.php”.

Affected products

  • Janto Janto: version 4.3r11 only

Published 2024-10-24. Last modified 2026-06-17.