Path traversal in Totaljs CMS - #VU20846
Published: September 4, 2019 / Updated: September 4, 2019
Totaljs CMS
Detailed vulnerability description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote authenticated user with “Pages” privilege can include arbitrary .html files that are outside the permitted directory and execute malicious template directive to gain remote code execution.