vendor:
TITAN File
by:
LiquidWorm
N/A
CVSS
N/A
Server-Side Request Forgery (SSRF)
CWE
Product Name: TITAN File
Affected Version From: 3.9.12.4
Affected Version To: 3.9.8.0
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows, NodeJS, Ateme KFE Software
2023
Ateme TITAN File 3.9 – SSRF File Enumeration
Authenticated Server-Side Request Forgery (SSRF) vulnerability exists in the Titan File video transcoding software. The application parses user supplied data in the job callback url GET parameter. Since no validation is carried out on the parameter, an attacker can specify an external domain and force the application to make an HTTP/DNS/File request to an arbitrary destination. This can be used by an external attacker for example to bypass firewalls and initiate a service, file and network enumeration on the internal network through the affected application.