CVE-2019-15953
 
Severity Score
8.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the associated API. The product correctly manages privileges only for the front-end resource path, not for API requests. This leads to vertical and horizontal privilege escalation.
Se detectó un problema en Total.js CMS versión 12.0.0. Un usuario autenticado con privilegios limitados puede obtener acceso a un recurso que no le pertenece llamando a la API asociada. El producto gestiona correctamente los privilegios solo para la ruta de recursos front-end, no para las solicitudes de API. Esto conduce a una escalada de privilegios vertical y horizontal.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-09-05 CVE Reserved
- 2019-09-05 CVE Published
- 2023-05-23 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-862: Missing Authorization
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/beerpwn/CVE/blob/master/Totaljs_disclosure_report/report_final.pdf | 2024-08-05 | |
https://seclists.org/fulldisclosure/2019/Sep/6 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Totaljs Search vendor "Totaljs" | Total.js Cms Search vendor "Totaljs" for product "Total.js Cms" | 12.0.0 Search vendor "Totaljs" for product "Total.js Cms" and version "12.0.0" | - |
Affected
|