vendor:
Total.js CMS
by:
Riccardo Krauter, sinn3r
9.9
CVSS
CRITICAL
Remote Code Execution
94
CWE
Product Name: Total.js CMS
Affected Version From: 12
Affected Version To: 12
Patch Exists: YES
Related CWE: CVE-2019-15954
CPE: a:totaljs:total.js_cms
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux, Mac
2019
Total.js CMS 12 Widget JavaScript Code Injection
This module exploits a vulnerability in Total.js CMS. The issue is that a user with admin permission can embed a malicious JavaScript payload in a widget, which is evaluated server side, and gain remote code execution.
Mitigation:
The user should not be given admin permission and the widget should be disabled.