Description
The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
References
https://github.com/totaljs/framework4/commit/8a72d8c20f38bbcac031a76a51238aa528f68821
PatchThird Party Advisory
https://snyk.io/vuln/SNYK-JS-TOTAL4-1130527
ExploitPatchThird Party Advisory
https://github.com/totaljs/framework4/commit/8a72d8c20f38bbcac031a76a51238aa528f68821
PatchThird Party Advisory
https://snyk.io/vuln/SNYK-JS-TOTAL4-1130527
ExploitPatchThird Party Advisory
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 · Critical
Information
Source identifier
Vulnerability status
Modified
Published
2021-07-12T16:15:09.030Z
5 years agoLast modified
2026-06-17T03:38:40.510Z
3 months ago