HIGH🇬🇧 English

CVE-2025-69240

CVSS 7.5v4.0pub. 2026-03-16

Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker (who knows the victim's email address) can force the server to send an email with password reset link pointing to the domain from spoofed header. When victim clicks the link, browser sends request to the attacker’s domain with the token in the path allowing the attacker to capture the token. This allows the attacker to reset victim's password and take over the victim's account. This issue was fixed in version 1.4.6.

oryginał EN
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Raytha

    APP
    Raytha
    < 1.4.6
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2025-15540HIGH8.6ten sam produkt

"Functions" module in Raytha CMS allows privileged users to write custom code to add functionality to applicat...

CVE-2025-69236MEDIUM5.1ten sam produkt

Raytha CMS jest podatny na Stored XSS poprzez parametr FieldValues[1].Value w funkcji edycji postów. Uwierzyte...

CVE-2025-69237MEDIUM5.1ten sam produkt

Raytha CMS jest podatny na Stored XSS poprzez parametr FieldValues[0].Value w funkcjonalności tworzenia stron....

CVE-2025-69238MEDIUM6.9ten sam produkt

Raytha CMS jest podatny na CSRF w wielu punktach końcowych. Atakujący może przygotować specjalną stronę intern...

CVE-2025-69239MEDIUM5.1ten sam produkt

Raytha CMS jest podatny na Server-Side Request Forgery w funkcji "Themes - Import from URL". Pozwala atakujące...