PT-2024-33175 · Unknown · Total.Js Cms

Piggyctf

·

Published

2024-10-25

·

Updated

2025-05-27

·

CVE-2024-48655

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Total.js CMS version 1.0
Description The issue allows a remote attacker to execute arbitrary code via the func.js file.
Recommendations For Total.js CMS version 1.0, update the func.js file to prevent arbitrary code execution or consider disabling the func.js file until a patch is available.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-48655

Affected Products

Total.Js Cms