CVE-2025-69240

Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker (who knows the victim's email address) can force the server to send an email with password reset link pointing to the domain from spoofed header. When victim clicks the link, browser sends request to the attacker’s domain with the token in the path allowing the attacker to capture the token. This allows the attacker to reset victim's password and take over the victim's account. This issue was fixed in version 1.4.6.
References
Link Resource
https://cert.pl/en/posts/2026/03/CVE-2025-69236 Third Party Advisory
https://raytha.com Product
Configurations

Configuration 1 (hide)

cpe:2.3:a:raytha:raytha:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:00

Type Values Removed Values Added
Summary
  • (es) Raytha CMS permite a un atacante suplantar los encabezados `X-Forwarded-Host` o `Host` a un dominio controlado por el atacante. El atacante (que conoce la dirección de correo electrónico de la víctima) puede forzar al servidor a enviar un correo electrónico con un enlace de restablecimiento de contraseña que apunta al dominio del encabezado suplantado. Cuando la víctima hace clic en el enlace, el navegador envía una solicitud al dominio del atacante con el token en la ruta, lo que permite al atacante capturar el token. Esto permite al atacante restablecer la contraseña de la víctima y tomar el control de la cuenta de la víctima. Este problema se solucionó en la versión 1.4.6.

16 Mar 2026, 19:30

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8
References () https://cert.pl/en/posts/2026/03/CVE-2025-69236 - () https://cert.pl/en/posts/2026/03/CVE-2025-69236 - Third Party Advisory
References () https://raytha.com - () https://raytha.com - Product
First Time Raytha raytha
Raytha
CPE cpe:2.3:a:raytha:raytha:*:*:*:*:*:*:*:*

16 Mar 2026, 14:18

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:18

Updated : 2026-06-17 10:00


NVD link : CVE-2025-69240

Mitre link : CVE-2025-69240

CVE.ORG link : CVE-2025-69240


JSON object : View

Products Affected

raytha

  • raytha
CWE
CWE-348

Use of Less Trusted Source