A critical security bug in Total.js Eshop + CMS
We have found a critical security bug in FileHandler, this blog contains instructions how to secure your websites.

A critical security bug in Total.js Eshop + CMS
We are really sorry, but this is life. Sometimes we are teachers and sometimes we are students. We found a critical security bug in Total.js Eshop and CMS yesterday. Please follow the instructions below:
- first reinstall Total.js to +v2.2.0 (
npm install total.js
) - check your source-code:
Open yourapp/controllers/default.js
and find a file_read
function and modify it as shown below:
FIX:
Do you have any questions? Contact use via our HelpDesk system.
We apologize for the inconvenience.
Other posts from Total.js Platform
- 2025-08-25IoT platform — Total.js
- 2025-08-22How to install OpenPlatform — IoT platform
- 2025-08-18Total.js Tables is here!
- 2025-08-18How to install Flow — IoT platform
- 2025-08-15How to install OpenReports — IoT platform
- 2025-08-08How to install stream to IoT platform — Total.js
- 2025-08-04July report 2025
- 2025-08-01How to install IoT platform — Total.js
- 2025-07-15Revolutionize Your IoT Management with Total.js IoT Platform: Simplify, Monitor, and Optimize
- 2025-07-01June report 2025