PT-2025-51311 · Ateme · Ateme Titan File
CVE-2023-53893
·
Publicado
2025-12-15
·
Atualizado
2025-12-21
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ateme TITAN File version 3.9.12.4
Description
The software contains an authenticated server-side request forgery issue in the job callback URL parameter. This allows attackers to bypass network restrictions. Exploitation involves an unvalidated parameter that enables file, service, and network enumeration by forcing the application to make HTTP, DNS, or file requests to arbitrary destinations. The vulnerable parameter is the
job callback URL.Recommendations
Apply a fix for Ateme TITAN File version 3.9.12.4 to address the server-side request forgery issue.
Exploit
Correção
SSRF
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ateme Titan File