PT-2024-17889 · Unknown · Antabot White-Jotter
Vastzero
·
Published
2024-12-30
·
Updated
2025-01-06
·
CVE-2024-13032
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Antabot White-Jotter versions up to 0.2.2
Description
A problematic issue has been found in the Article Editor component, specifically in the /admin/content/editor file, affecting an unknown functionality. The manipulation of the
articleCover argument leads to server-side request forgery. This issue can be exploited remotely. The exploit has been disclosed to the public and may be used.Recommendations
For versions up to 0.2.2, consider disabling the
articleCover argument in the /admin/content/editor file as a temporary workaround until a patch is available. Restrict access to the Article Editor component to minimize the risk of exploitation. Avoid using the articleCover argument in the affected functionality until the issue is resolved.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Antabot White-Jotter