mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-28 18:48:49 +00:00
905 B
905 B
CVE-2024-48655
Description
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
POC
Reference
- https://github.com/totaljs/cms/issues/49
- https://medium.com/%400x0d0x0a/cve-2024-48655-server-side-javascript-code-injection-in-total-js-cms-c5fc18359bdc
- https://medium.com/@0x0d0x0a/cve-2024-48655-server-side-javascript-code-injection-in-total-js-cms-c5fc18359bdc