// For flags

CVE-2019-15952

Totaljs CMS 12.0 Path Traversal

Severity Score

8.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .html files that are outside the permitted directory. Also, if a page contains a template directive, then the directive will be server side processed. Thus, if a user can control the content of a .html file, then they can inject a payload with a malicious template directive to gain Remote Command Execution. The exploit will work only with the .html extension.

Se detecto un error en Total.js CMS versión 12.0.0. Un usuario autenticado con el privilegio de Páginas puede realizar un ataque transversal de ruta (../) para incluir archivos .html que están fuera del directorio permitido. Además, si una página contiene una directiva de plantilla, la directiva se procesará en el servidor. Por lo tanto, si un usuario puede controlar el contenido de un archivo .html, puede inyectar una carga útil con una directiva de plantilla maliciosa para obtener la Ejecución Remota de Comandos. La explotación solo funcionará con la extensión .html.

Totaljs CMS version 12.0 suffers from a path traversal vulnerability.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-09-03 CVE Published
  • 2019-09-05 CVE Reserved
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • 2024-08-29 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Totaljs
Search vendor "Totaljs"
Total.js Cms
Search vendor "Totaljs" for product "Total.js Cms"
12.0.0
Search vendor "Totaljs" for product "Total.js Cms" and version "12.0.0"
-
Affected