CVE-2023-53893
Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass network restrictions. Attackers can exploit the unvalidated parameter to initiate file, service, and network enumeration by forcing the application to make HTTP, DNS, or file requests to arbitrary destinations.
Vendor
Product
CWE
Yayın Tarihi
2025-12-15 21:15:52
Güncelleme
2025-12-18 21:36:17
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-
Kategoriler
Referanslar
https://www.ateme.com/product-titan-software/
https://www.exploit-db.com/exploits/51582
https://www.vulncheck.com/advisories/ateme-titan-file-authenticated-server-side-request-forgery-vulnerability
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5781.php
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5781.php