CVE-2019-15952
Totaljs CMS 12.0 Path Traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .html files that are outside the permitted directory. Also, if a page contains a template directive, then the directive will be server side processed. Thus, if a user can control the content of a .html file, then they can inject a payload with a malicious template directive to gain Remote Command Execution. The exploit will work only with the .html extension.
Se detecto un error en Total.js CMS versión 12.0.0. Un usuario autenticado con el privilegio de Páginas puede realizar un ataque transversal de ruta (../) para incluir archivos .html que están fuera del directorio permitido. Además, si una página contiene una directiva de plantilla, la directiva se procesará en el servidor. Por lo tanto, si un usuario puede controlar el contenido de un archivo .html, puede inyectar una carga útil con una directiva de plantilla maliciosa para obtener la Ejecución Remota de Comandos. La explotación solo funcionará con la extensión .html.
Totaljs CMS version 12.0 suffers from a path traversal vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-09-03 CVE Published
- 2019-09-05 CVE Reserved
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-08-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/154340/Totaljs-CMS-12.0-Path-Traversal.html | X_refsource_misc | |
http://seclists.org/fulldisclosure/2019/Sep/11 | Mailing List |
URL | Date | SRC |
---|---|---|
https://github.com/beerpwn/CVE/blob/master/Totaljs_disclosure_report/report_final.pdf | 2024-08-05 | |
https://seclists.org/fulldisclosure/2019/Sep/2 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Totaljs Search vendor "Totaljs" | Total.js Cms Search vendor "Totaljs" for product "Total.js Cms" | 12.0.0 Search vendor "Totaljs" for product "Total.js Cms" and version "12.0.0" | - |
Affected
|