Vulnerability record · CVE-2019-15954 · published 5 September 2019
CVE-2019-15954: Total.js CMS widget tag sandbox escape leads to RCE
Totaljs · Total.Js Cms
Total.js CMS 12.0.0 evaluates widget tag content server side, and an authenticated user holding the widgets privilege can escape the sandbox object with a crafted <script total> tag. The flaw is classified as missing authorization (CWE-862) and carries a CVSS 3.1 base score of 9.9, so it matters because a low-privileged account can reach full server compromise.
Description
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript code that will be evaluated server side. In the process of evaluating the tag by the back-end, it is possible to escape the sandbox object by using the following payload: <script total>global.process.mainModule.require(child_process).exec(RCE);</script>
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.9 with network reachability, low privileges required, scope change, and public exploit code plus very high EPSS make this a top remediation priority.
What it is
Total.js CMS 12.0.0 evaluates widget tag content server side, and an authenticated user holding the widgets privilege can escape the sandbox object with a crafted <script total> tag. The flaw is classified as missing authorization (CWE-862) and carries a CVSS 3.1 base score of 9.9, so it matters because a low-privileged account can reach full server compromise.
Impact
The attacker executes arbitrary operating system commands on the remote server with the privileges of the CMS process, giving full control of the host and any data or credentials it can reach.
Attack surface
Reached over the network through the widget creation functionality of the CMS; the attacker must be authenticated and hold the widgets privilege, and no user interaction is required.
Exploitation
Public exploit write-ups exist (Packet Storm, Full Disclosure, and a GitHub disclosure report), and EPSS is 0.78691 (99.568th percentile), indicating high predicted exploitation activity; the CVE is not listed in CISA KEV.
What to do
- Upgrade Total.js CMS past 12.0.0 to a release that fixes the widget tag sandbox escape; no fixed version is stated in this record, so confirm with the vendor.
- Restrict the widgets privilege to trusted administrators and review all accounts currently holding it.
- Run the CMS under a low-privileged service account with no access to sensitive files or the host shell.
- Block or filter widget content containing <script total> tags and server-side JavaScript evaluation until patched.
- Place the CMS behind network controls so it is not directly reachable from untrusted networks.
Detection
- Search CMS widget content and logs for <script total> tags or references to global.process.mainModule.require and child_process.
- Alert on unexpected child processes spawned by the CMS server process (for example shell or command interpreters).
- Monitor for outbound connections or file writes originating from the CMS process that are inconsistent with normal operation.
- Audit creation and modification of widgets, especially by accounts that do not normally use the widgets privilege.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/154924/Total.js-CMS-12-Widget-JavaScript-Code-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/beerpwn/CVE/blob/master/Totaljs_disclosure_report/report_final.pdf | ExploitThird Party Advisory |
| https://seclists.org/fulldisclosure/2019/Sep/5 | ExploitMailing ListThird Party Advisory |
| http://packetstormsecurity.com/files/154924/Total.js-CMS-12-Widget-JavaScript-Code-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/beerpwn/CVE/blob/master/Totaljs_disclosure_report/report_final.pdf | ExploitThird Party Advisory |
| https://seclists.org/fulldisclosure/2019/Sep/5 | ExploitMailing ListThird Party Advisory |
Track CVE-2019-15954 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-15954), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.