CVE-2024-13029 MEDIUM

CVE-2024-13029: Antabot White-Jotter Edit Book book server-side request forgery

Vendor Antabot
Product White-Jotter
Weakness CWE-918 · SSRF
Published December 29, 2024
Last update December 30, 2024

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A vulnerability, which was classified as problematic, was found in Antabot White-Jotter up to 0.2.2. Affected is an unknown function of the file /admin/content/book of the component Edit Book Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Key dates

02Disclosure timeline

December 29, 2024 CVE published
December 30, 2024 Record updated