Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
agentejo vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2020-35848
Agentejo Cockpit prior to 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
Agentejo Cockpit
1 Github repository
6.1
CVSSv3
CVE-2021-32857
Cockpit is a content management system that allows addition of content management functionality to any site. In versions 0.12.2 and prior, bad HTML sanitization in `htmleditor.js` may lead to cross-site scripting (XSS) issues. There are no known patches for this issue.
Agentejo Cockpit
7.5
CVSSv3
CVE-2023-37649
Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized malicious users to access sensitive data.
Agentejo Cockpit
8.8
CVSSv3
CVE-2023-37650
A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows malicious users to execute arbitrary Administrator commands.
Agentejo Cockpit
6.1
CVSSv3
CVE-2023-41564
An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows malicious users to execute arbitrary code via uploading a crafted .shtml file.
Agentejo Cockpit 2.6.3
6.1
CVSSv3
CVE-2020-14408
An issue exists in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.
Agentejo Cockpit 0.10.2
9.1
CVSSv3
CVE-2017-14611
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote malicious users to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.
Agentejo Cockpit 0.13.0
NA
CVE-2024-4825
A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.
6.5
CVSSv3
CVE-2020-35850
An SSRF issue exists in cockpit-project.org Cockpit 234. NOTE: this is unrelated to the Agentejo Cockpit product. NOTE: the vendor states "I don't think [it] is a big real-life issue.
Cockpit-project Cockpit 234
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
denial of service
CVE-2024-27371
CVE-2024-20405
CVE-2024-31627
CVE-2024-31625
race condition
CVE-2024-4358
cross-site scripting
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3