Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass network restrictions. Attackers can exploit the unvalidated parameter to initiate file, service, and network enumeration by forcing the application to make HTTP, DNS, or file requests to arbitrary destinations.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass network restrictions. Attackers can exploit the unvalidated parameter to initiate file, service, and network enumeration by forcing the application to make HTTP, DNS, or file requests to arbitrary destinations. | |
| Title | Ateme TITAN File 3.9 Authenticated Server-Side Request Forgery Vulnerability | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-15T20:28:25.098Z
Updated: 2025-12-15T21:46:06.259Z
Reserved: 2025-12-15T14:48:57.139Z
Link: CVE-2023-53893
Updated: 2025-12-15T21:37:01.190Z
Status : Received
Published: 2025-12-15T21:15:52.683
Modified: 2025-12-15T22:15:47.367
Link: CVE-2023-53893
No data.