CVE-2025-1108: Impronta Janto
High severity, CVSS 8.6. EPSS: 0.2% chance of exploitation in the next 30 days.
Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This allows an unauthenticated attacker to modify the content of emails sent to reset the password. To exploit the vulnerability, the attacker must create a POST request by injecting malicious content into the ‘Xml’ parameter on the ‘/public/cgi/Gateway.php’ endpoint.
Affected products
- Impronta Janto: before r12 (fixed in r12)
Published 2025-02-07. Last modified 2026-06-17.