SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-15954

An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side.

CRITICAL 9.9EPSS 78.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 78.7%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side. In the process of evaluating the tag by the back-end, it is possible to escape the sandbox object by using the following payload: <script total>global.process.mainModule.require(child_process).exec(RCE);</script>

CVSS 3.1
9.9 CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
EPSS
78.69% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-862
Affected
totaljs/total.js cms
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.