Description
The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
References
https://github.com/totaljs/framework4/commit/8a72d8c20f38bbcac031a76a51238aa528f68821
PatchThird Party Advisory
https://snyk.io/vuln/SNYK-JS-TOTAL4-1130527
ExploitPatchThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 · Critical
CVSS V3.1
CVSS V3.0
CVSS V2.0
Information
Source identifier
Vulnerability status
Analyzed
Published
2021-07-12T16:15:09.030
3 years agoLast modified
2021-07-14T17:38:45.477
3 years ago