Product:

Cockpit

(Agentejo)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 29
Date Id Summary Products Score Patch Annotated
2024-05-14 CVE-2024-4825 A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure. Cockpit N/A
2024-02-29 CVE-2024-2001 A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded. Cockpit 5.4
2020-06-17 CVE-2020-14408 An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector. Cockpit 6.1
2020-12-30 CVE-2020-35846 Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function. Cockpit 9.8
2020-12-30 CVE-2020-35847 Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function. Cockpit 9.8
2020-12-30 CVE-2020-35848 Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function. Cockpit 9.8
2021-01-08 CVE-2020-35131 Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI. Cockpit 9.8
2022-08-08 CVE-2022-2713 Insufficient Session Expiration in GitHub repository cockpit-hq/cockpit prior to 2.2.0. Cockpit 9.8
2022-08-15 CVE-2022-2818 Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2. Cockpit 8.8
2023-02-09 CVE-2023-0759 Privilege Chaining in GitHub repository cockpit-hq/cockpit prior to 2.3.8. Cockpit 8.8