CVE-2020-35848
CRITICALNuclei
Cockpit CMS 0.11.1 - 'Username Enumeration & Password Reset' NoSQL Injection
Record summary
CVE-2020-35848 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit, 2 repository PoCs, and 1 Nuclei template.
Proofs of concept
3Catalogued exploits
ExploitDBCockpit CMS 0.11.1 - 'Username Enumeration & Password Reset' NoSQL InjectionExploitDB exploitby Brian OmbongiNot analyzed1 file
Repository PoCs
GitHubsabbu143s/CVE_2020_35848Repository PoCby sabbu143sStars: 0Not analyzed3 files
GitHubw33vils/CVE-2020-35847_CVE-2020-35848Repository PoCby w33vilsStars: 0Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALAgentejo Cockpit <0.12.0 - NoSQL InjectionCVSS 9.8
Agentejo Cockpit prior to 0.12.0 is vulnerable to NoSQL Injection via the newpassword method of the Auth controller, which is responsible for displaying the user password reset form.
Impact
Successful exploitation of this vulnerability could allow an attacker to manipulate database queries, potentially leading to unauthorized access, data leakage, or data corruption.
Remediation
Upgrade Agentejo Cockpit to version 0.12.0 or later to mitigate this vulnerability.
WeaknessesCWE-89
Authorsdwisiswant0
Template tagscvecve2020nosqlisqlicockpitinjectionagentejovuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:agentejo:cockpit:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:688609340
Shodan: http.html:"cockpit"
FOFA: icon_hash=688609340
FOFA: body="cockpit"
https://swarm.ptsecurity.com/rce-cockpit-cms/ https://nvd.nist.gov/vuln/detail/CVE-2020-35848 https://getcockpit.com/ https://github.com/agentejo/cockpit/commit/2a385af8d80ed60d40d386ed813c1039db00c466 https://github.com/agentejo/cockpit/commit/33e7199575631ba1f74cba6b16b10c820bec59af
Source: ProjectDiscovery
References
6packetstormsecurity.com
http://packetstormsecurity.com/files/163762/Cockpit-CMS-0.11.1-NoSQL-Injection.html getcockpit.com
https://getcockpit.com/ github.com
https://github.com/agentejo/cockpit/commit/2a385af8d80ed60d40d386ed813c1039db00c466 github.com
https://github.com/agentejo/cockpit/commit/33e7199575631ba1f74cba6b16b10c820bec59af github.com
https://github.com/agentejo/cockpit/commit/79fc9631ffa29146e3124ceaf99879b92e1ef24b nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-35848