Executive brief
Total.js CMS is a content management system used to build and manage websites. An authenticated user with page editing privileges can exploit a path traversal vulnerability to include HTML files from outside the intended directory, and then inject malicious template code to execute arbitrary commands on the server.
Technical details
The vulnerability is a path traversal issue (CWE-22) in Total.js CMS version 12.0.0 affecting the page inclusion functionality. An authenticated user with the Pages privilege can use directory traversal sequences (../) to access .html files outside the intended directory. If a traversed .html file contains template directives, the server processes them server-side, allowing template injection. An attacker who controls the content of an accessible .html file can inject malicious template directives to achieve remote code execution. The vulnerability requires authentication and the Pages privilege to exploit, and works only with .html file extensions.
Affected products
- Total.js CMS 12.0.0
Timeline
- 2019-09: disclosed: Vulnerability disclosed via full-disclosure mailing list
- 2022-05-24: advisory: GitHub Security Advisory published