216.73.216.226

CVE-2025-69240

· Published 16/03/2026 14:18 · Modified 16/03/2026 19:30

Labels: CVE-2025-69240 2026-03-16CVE-2025-69240CWE-348[email protected]

Essential information

Published
16/03/2026 14:18
Modified
16/03/2026 19:30
Author
Creator
CVSS
7.5 HIGH (v3) 7.5 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker (who knows the victim's email address) can force the server to send an email with password reset link pointing to the domain from spoofed header. When victim clicks the link, browser sends request to the attacker’s domain with the token in the path allowing the attacker to capture the token. This allows the attacker to reset victim's password and take over the victim's account. This issue was fixed in version 1.4.6.

NVD status

Status
Analyzed — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
raytha / raytha cpe:2.3:a:raytha:raytha:*:*:*:*:*:*:*:*

References