A critical security bug in Total.js Eshop + CMS
We have found a critical security bug in FileHandler, this blog contains instructions how to secure your websites.
A critical security bug in Total.js Eshop + CMS
We are really sorry, but this is life. Sometimes we are teachers and sometimes we are students. We found a critical security bug in Total.js Eshop and CMS yesterday. Please follow the instructions below:
- first reinstall Total.js to +v2.2.0 (
npm install total.js
) - check your source-code:
Open yourapp/controllers/default.js
and find a file_read
function and modify it as shown below:
FIX:
Do you have any questions? Contact use via our HelpDesk system.
We apologize for the inconvenience.
Other posts from Total.js Platform
- 2024-11-13Benchmarking Node.js Frameworks: selecting your framework for 2025!
- 2024-11-01October report 2024
- 2024-10-22Performance Testing: Total.js vs. NestJS
- 2024-10-01September report 2024
- 2024-09-27Total.js UI Builder: #2 designing your first interface
- 2024-09-26Total.js V5: Middlewares
- 2024-09-23Beginner Guide to Total.js UI: # 05 Client-side routing
- 2024-09-23Total.js UI #4: Data Binding (Part 2 – Practical Example)
- 2024-09-20Introduction to Total.js UI Builder: A Beginner’s Guide
- 2024-09-13Total.js v5: #06 Understanding File Routing