Description
Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. In total.js framework before version 3.4.9, calling the utils.set function with user-controlled values leads to code-injection. This can cause a variety of impacts that include arbitrary code execution. This is fixed in version 3.4.9.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-2121 | Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. In total.js framework before version 3.4.9, calling the utils.set function with user-controlled values leads to code-injection. This can cause a variety of impacts that include arbitrary code execution. This is fixed in version 3.4.9. |
Github GHSA |
GHSA-vwhc-pww7-72x6 | Code Injection in total.js |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-03T23:33:56.088Z
Reserved: 2021-05-12T00:00:00.000Z
Link: CVE-2021-32831
No data.
Status : Modified
Published: 2021-08-30T21:15:09.287
Modified: 2024-11-21T06:07:50.480
Link: CVE-2021-32831
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA