CVE-2024-48655
HIGH 8.8EPSS 1.0%
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 1.03% chance of exploitation in the next 30 days, 61th percentile
- Published
- 2024-10-25
- Updated
- 2024-10-29
Proof-of-concept exploits (2)
- totaljs/cms/issues/49
- https://medium.com/%400x0d0x0a/cve-2024-48655-server-side-javascript-code-injection-in-to…