index.js in Total.js Platform before 3.2.3 allows path traversal.
References
Link | Resource |
---|---|
https://github.com/totaljs/framework/commit/de16238d13848149f5d1dae51f54e397a525932b | Patch Third Party Advisory |
https://github.com/totaljs/framework/commit/c37cafbf3e379a98db71c1125533d1e8d5b5aef7 | Patch Third Party Advisory |
https://blog.certimetergroup.com/it/articolo/security/total.js-directory-traversal-cve-2019-8903 |
Configurations
Information
Published : 2019-02-18 08:29
Updated : 2020-03-18 12:15
NVD link : CVE-2019-8903
Mitre link : CVE-2019-8903
JSON object : View
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Products Affected
totaljs
- total.js