Antabot White-Jotter Unauthenticated Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in Antabot White-Jotter, all versions prior to commit 9bcadc. This vulnerability arises from improper access control in the Shiro configuration, combined with unsafe log4j usage, allowing unauthenticated users to execute arbitrary commands.

Impact

Exploitation of this vulnerability allows for unauthenticated remote code execution on the server where White-Jotter is hosted.

Reproduction

To reproduce this vulnerability, send a POST request to '/api/aaa;/../register' with a payload that includes a username formatted as a JNDI LDAP injection (pointing to a local LDAP server) and other required registration details. After the user is registered, log in using the injected username to obtain a session cookie. Finally, access an admin endpoint, such as '/api/admin/content/article', to trigger the command execution via the injected JNDI payload.

Added: Oct 24, 2025, 4:34 PM
Updated: Oct 24, 2025, 6:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.0
remediation
0.0
relevance
0.8
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.