CVE-2019-15953 describes a critical privilege escalation vulnerability in Total.js CMS version 12.0.0. An authenticated user with limited privileges can bypass front-end access controls by directly interacting with the API, leading to both vertical and horizontal privilege escalation. This vulnerability has a CVSS score of 8.8 (High), indicating that it is easily exploitable over the network with low attack complexity, and can result in high impact to confidentiality, integrity, and availability. While no public exploits or active exploitation have been reported, and community discussion is minimal, the inherent risk remains significant.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.0.0CPE matchmatch criteria | cpe:2.3:a:totaljs:total.js_cms:12.0.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.