CVE-2020-10790

MEDIUM

openITCOCKPIT < 3.7.3 - Cross-Site Scripting via Unnecessary Files Under Web Root

Title source: llm
STIX 2.1

Description

openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.

Scores

CVSS v3 5.4
EPSS 0.0091
EPSS Percentile 55.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
it-novum/openitcockpit < 3.7.3
Published Mar 25, 2020
Tracked Since Feb 18, 2026