High severity8.8NVD Advisory· Published Sep 5, 2019· Updated Jun 17, 2026
CVE-2019-15952
CVE-2019-15952
Description
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the Pages privilege can conduct a path traversal attack (../) to include .html files that are outside the permitted directory. Also, if a page contains a template directive, then the directive will be server side processed. Thus, if a user can control the content of a .html file, then they can inject a payload with a malicious template directive to gain Remote Command Execution. The exploit will work only with the .html extension.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:totaljs:total.js_cms:12.0.0:*:*:*:*:*:*:*
- Total.js/Total.js CMSdescription
- ghsa-coords
Patches
Vulnerability mechanics
References
6- github.com/beerpwn/CVE/blob/master/Totaljs_disclosure_report/report_final.pdfnvdExploitThird Party AdvisoryWEB
- seclists.org/fulldisclosure/2019/Sep/2nvdExploitMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-pwvp-h579-hfxgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-15952ghsaADVISORY
- packetstormsecurity.com/files/154340/Totaljs-CMS-12.0-Path-Traversal.htmlnvd
- seclists.org/fulldisclosure/2019/Sep/11nvd
News mentions
0No linked articles in our index yet.