Deserialization Vulnerability in Antabot White-Jotter by Antabot
CVE-2025-8708
Key Information:
- Vendor
Antabot
- Status
- Vendor
- CVE Published:
- 8 August 2025
Badges
What is CVE-2025-8708?
A vulnerability exists in Antabot White-Jotter version 0.22 related to the CookieRememberMeManager function found in ShiroConfiguration.java. This issue allows an attacker to manipulate input data, specifically the parameter EVANNIGHTLY_WAOU, resulting in deserialization vulnerabilities that can be exploited remotely. The complexity associated with exploiting this vulnerability is notably high, and while public knowledge of the exploit exists, successful implementation may prove challenging.
Affected Version(s)
White-Jotter 0.22
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved