A vulnerability classified as problematic was found in Antabot White-Jotter up to 0.2.2. Affected by this vulnerability is an unknown functionality of the file /admin/content/editor of the component Article Editor. The manipulation of the argument articleCover leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 06 Jan 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Antabot
Antabot white-jotter
CPEs cpe:2.3:a:antabot:white-jotter:*:*:*:*:*:*:*:*
Vendors & Products Antabot
Antabot white-jotter

Mon, 30 Dec 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Dec 2024 01:30:00 +0000

Type Values Removed Values Added
Description A vulnerability classified as problematic was found in Antabot White-Jotter up to 0.2.2. Affected by this vulnerability is an unknown functionality of the file /admin/content/editor of the component Article Editor. The manipulation of the argument articleCover leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Title Antabot White-Jotter Article Editor editor server-side request forgery
Weaknesses CWE-918
References
Metrics cvssV2_0

{'score': 3.3, 'vector': 'AV:N/AC:L/Au:M/C:N/I:P/A:N'}

cvssV3_0

{'score': 2.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}

cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2024-12-30T14:40:45.431Z

Reserved: 2024-12-29T12:29:12.074Z

Link: CVE-2024-13032

cve-icon Vulnrichment

Updated: 2024-12-30T14:40:40.879Z

cve-icon NVD

Status : Analyzed

Published: 2024-12-30T02:15:06.260

Modified: 2025-01-06T18:47:07.217

Link: CVE-2024-13032

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.