Логотип exploitDog
bind:CVE-2019-15954
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-15954

Количество 2

Количество 2

nvd логотип

CVE-2019-15954

больше 6 лет назад

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side. In the process of evaluating the tag by the back-end, it is possible to escape the sandbox object by using the following payload: <script total>global.process.mainModule.require(child_process).exec(RCE);</script>

CVSS3: 9.9
EPSS: Средний
github логотип

GHSA-v287-9w3v-x5c5

больше 3 лет назад

Total.js CMS RCE Vulnerability

CVSS3: 9.9
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-15954

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side. In the process of evaluating the tag by the back-end, it is possible to escape the sandbox object by using the following payload: <script total>global.process.mainModule.require(child_process).exec(RCE);</script>

CVSS3: 9.9
57%
Средний
больше 6 лет назад
github логотип
GHSA-v287-9w3v-x5c5

Total.js CMS RCE Vulnerability

CVSS3: 9.9
57%
Средний
больше 3 лет назад

Уязвимостей на страницу