CVE Explorer
CVE-2025-69240
Raytha CMS allows an attacker to spoof `X-Forwarded-Host` or `Host` headers to attacker controlled domain. The attacker (who knows the victim's email address) can force the server to send an email with password reset link pointing to the domain from spoofed header. When victim clicks the link, browser sends request to the attacker’s domain with the token in the path allowing the attacker to capture the token. This allows the attacker to reset victim's password and take over the victim's account.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Raytha","repo":"https://github.com/raythahq/raytha","vendor":"Raytha","versions":[{"lessThan":"1.4.6","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b97733e2741af4cbdb70ff2245e6bbad3400e306f98aa663971244dfb438aa72 · sha256:0e3df6ad8ab28e42… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":7.5,"baseSeverity":"HIGH","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b97733e2741af4cbdb70ff2245e6bbad3400e306f98aa663971244dfb438aa72 · sha256:0e3df6ad8ab28e42… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-348","description":"CWE-348 Use of Less Trusted Source","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b97733e2741af4cbdb70ff2245e6bbad3400e306f98aa663971244dfb438aa72 · sha256:0e3df6ad8ab28e42… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"tags":["third-party-advisory"],"url":"https://cert.pl/en/posts/2026/03/CVE-2025-69236"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b97733e2741af4cbdb70ff2245e6bbad3400e306f98aa663971244dfb438aa72 · sha256:0e3df6ad8ab28e42… · /containers/cna/references/0
{"tags":["product"],"url":"https://raytha.com"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b97733e2741af4cbdb70ff2245e6bbad3400e306f98aa663971244dfb438aa72 · sha256:0e3df6ad8ab28e42… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.