Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31880
HistoryAug 31, 2021 - 6:23 a.m.

Remote Code Execution (RCE)

2021-08-3106:23:33
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
total.js
remote code execution
lack of sanitization
user-provided values
function injection
malicious code
software

EPSS

0.006

Percentile

79.0%

total.js is vulnerable to remote code execution. Lack of sanitization of user-provided values allows an attacker to inject and execute malicious code via the function utils.set.

EPSS

0.006

Percentile

79.0%