Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: GSA_kwCzR0hTQS12Mjg3LTl3M3YteDVjNc4AAh-W

Total.js CMS RCE Vulnerability

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side. In the process of evaluating the tag by the back-end, it is possible to escape the sandbox object by using the following payload: <script total>global.process.mainModule.require(child_process).exec(RCE);</script>

Permalink: https://github.com/advisories/GHSA-v287-9w3v-x5c5
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS12Mjg3LTl3M3YteDVjNc4AAh-W
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Critical
Classification: General
Published: over 2 years ago
Updated: over 1 year ago


CVSS Score: 10.0
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS Percentage: 0.35524
EPSS Percentile: 0.97244

Identifiers: GHSA-v287-9w3v-x5c5, CVE-2019-15954
References: Repository: https://github.com/beerpwn/CVE
Blast Radius: 28.1

Affected Packages

npm:total4
Dependent packages: 6
Dependent repositories: 643
Downloads: 1,326 last month
Affected Version Ranges: = 12.0.0
No known fixed version
All affected versions: