CVE-2019-15954 | Total.js CMS 12.0.0 Widget command injection (ID 154924 / EDB-47531)
A vulnerability was found in Total.js CMS 12.0.0 and classified as critical. This issue affects some unknown processing of the component Widget Handler. The manipulation with the input <script total>global.process.mainModule.require(child_process).exec(RCE);</script> leads to command injection.
The identification of this vulnerability is CVE-2019-15954. The attack may be initiated remotely. Furthermore, there is an exploit available.