Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
it-novum openitcockpit vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-3520
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit before 4.6.6.
It-novum Openitcockpit
NA
CVE-2023-36663
it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 prior to 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface.
It-novum Openitcockpit 4.6.4
NA
CVE-2023-3218
Race Condition within a Thread in GitHub repository it-novum/openitcockpit before 4.6.5.
It-novum Openitcockpit
570
VMScore
CVE-2020-10788
openITCOCKPIT prior to 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections.
It-novum Openitcockpit
890
VMScore
CVE-2020-10789
openITCOCKPIT prior to 3.7.3 has a web-based terminal that allows malicious users to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php.
It-novum Openitcockpit
312
VMScore
CVE-2020-10790
openITCOCKPIT prior to 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.
It-novum Openitcockpit
356
VMScore
CVE-2020-10791
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT prior to 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.
It-novum Openitcockpit
445
VMScore
CVE-2020-10792
openITCOCKPIT up to and including 3.7.2 allows remote malicious users to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
It-novum Openitcockpit
435
VMScore
CVE-2019-10227
openITCOCKPIT prior to 3.7.1 has reflected XSS in the 404-not-found component.
It-novum Openitcockpit
1 EDB exploit
605
VMScore
CVE-2019-15491
openITCOCKPIT prior to 3.7.1 has CSRF, aka RVID 2-445b21.
It-novum Openitcockpit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
buffer overflow
type confusion
server-side request forgery
CVE-2024-38440
CVE-2024-27801
CVE-2024-5868
CVE-2024-0582
CVE-2024-37643
CVE-2024-3105
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »