CVE-2020-10791

MEDIUM

openITCOCKPIT <3.7.3 - Authenticated SSRF

Title source: llm
STIX 2.1

Description

app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.

Scores

CVSS v3 6.5
EPSS 0.0014
EPSS Percentile 33.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-918
Status published
Products (1)
it-novum/openitcockpit < 3.7.3
Published Mar 25, 2020
Tracked Since Feb 18, 2026