total.js Remote Code Execution Vulnerability
Critical severity
GitHub Reviewed
Published
Mar 19, 2021
to the GitHub Advisory Database
•
Updated Sep 13, 2023
Description
Published by the National Vulnerability Database
Mar 4, 2021
Reviewed
Mar 12, 2021
Published to the GitHub Advisory Database
Mar 19, 2021
Last updated
Sep 13, 2023
total.js is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. It can be used as web, desktop, service or IoT application.
Affected versions of this package are vulnerable to Remote Code Execution (RCE) via
set
.PoC
References