Totaljs
Totaljs Total.js CMS: vulnerabilidades y CVE
Totaljs Total.js CMS tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-9381 | Alta (7.5) | 2.1% | — | 24 feb 2020 | controllers/admin.js in Total.js CMS 13 allows remote attackers to execute arbitrary code via a POST to the /admin/api/widgets/ URI. This can be exploited in conjunction with CVE-2019-15954. |
| CVE-2019-15955 | Media (6.5) | 0.87% | — | 5 sept 2019 | An issue was discovered in Total.js CMS 12.0.0. A low privilege user can perform a simple transformation of a cookie to obtain the random values inside it. If an attacker can discover a session cookie owned by an admin,… |
| CVE-2019-15954 | Crítica (9.9) | 79% | — | 5 sept 2019 | An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag… |
| CVE-2019-15953 | Alta (8.8) | 1.5% | — | 5 sept 2019 | An issue was discovered in Total.js CMS 12.0.0. An authenticated user with limited privileges can get access to a resource that they do not own by calling the associated API. The product correctly manages privileges… |
| CVE-2019-15952 | Alta (8.8) | 5.1% | — | 5 sept 2019 | An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .html files that are outside the permitted directory. Also, if a page… |
| CVE-2019-10260 | Media (6.1) | 0.91% | — | 28 mar 2019 | Total.js CMS 12.0.0 has XSS related to themes/admin/views/index.html (item.message) and themes/admin/public/ui.js (column.format). |