Authenticated Server-Side Request Forgery in Ateme TITAN File
CVE-2023-53893
Key Information:
Badges
What is CVE-2023-53893?
Ateme TITAN File version 3.9.12.4 has a vulnerability that enables authenticated users to exploit an unvalidated callback URL parameter in job requests. This weakness allows attackers to bypass network restrictions, potentially leading to unauthorized access and the ability to enumerate files, services, and networks. By manipulating the application into making requests to arbitrary endpoints, the vulnerability poses significant risks to the integrity and confidentiality of network communications.
Affected Version(s)
TITAN 3.9.12.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
