Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass network restrictions. Attackers can exploit the unvalidated parameter to initiate file, service, and network enumeration by forcing the application to make HTTP, DNS, or file requests to arbitrary destinations.
References
| Link | Resource |
|---|---|
| https://www.ateme.com/product-titan-software/ | Product |
| https://www.exploit-db.com/exploits/51582 | Exploit Third Party Advisory |
| https://www.vulncheck.com/advisories/ateme-titan-file-authenticated-server-side-request-forgery-vulnerability | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5781.php | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5781.php | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
18 Dec 2025, 21:36
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.ateme.com/product-titan-software/ - Product | |
| References | () https://www.exploit-db.com/exploits/51582 - Exploit, Third Party Advisory | |
| References | () https://www.vulncheck.com/advisories/ateme-titan-file-authenticated-server-side-request-forgery-vulnerability - Third Party Advisory | |
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5781.php - Third Party Advisory | |
| First Time |
Ateme
Ateme titan File |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
| CPE | cpe:2.3:a:ateme:titan_file:3.9.8.0:*:*:*:*:*:*:* cpe:2.3:a:ateme:titan_file:3.9.12.4:*:*:*:*:*:*:* cpe:2.3:a:ateme:titan_file:3.9.9.2:*:*:*:*:*:*:* cpe:2.3:a:ateme:titan_file:3.9.11.0:*:*:*:*:*:*:* |
15 Dec 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.zeroscience.mk/en/vulnerabilities/ZSL-2023-5781.php - |
15 Dec 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-15 21:15
Updated : 2025-12-18 21:36
NVD link : CVE-2023-53893
Mitre link : CVE-2023-53893
CVE.ORG link : CVE-2023-53893
JSON object : View
Products Affected
ateme
- titan_file
CWE
CWE-918
Server-Side Request Forgery (SSRF)
