Record summary

CVE-2020-35848 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit, 2 repository PoCs, and 1 Nuclei template.

Description

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
2
Nuclei templates
1

Proofs of concept

3

Catalogued exploits

ExploitDBCockpit CMS 0.11.1 - 'Username Enumeration & Password Reset' NoSQL InjectionExploitDB exploitby Brian OmbongiNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

Repository PoCs

GitHubsabbu143s/CVE_2020_35848Repository PoCby sabbu143sStars: 0Not analyzed3 files

3.9 KiB

GitHub

PoC details
GitHubw33vils/CVE-2020-35847_CVE-2020-35848Repository PoCby w33vilsStars: 0Not analyzed2 files

6.8 KiB · linked to 2 vulnerabilities

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALAgentejo Cockpit <0.12.0 - NoSQL InjectionCVSS 9.8

Agentejo Cockpit prior to 0.12.0 is vulnerable to NoSQL Injection via the newpassword method of the Auth controller, which is responsible for displaying the user password reset form.

Impact

Successful exploitation of this vulnerability could allow an attacker to manipulate database queries, potentially leading to unauthorized access, data leakage, or data corruption.

Remediation

Upgrade Agentejo Cockpit to version 0.12.0 or later to mitigate this vulnerability.

WeaknessesCWE-89
Authorsdwisiswant0
Template tagscvecve2020nosqlisqlicockpitinjectionagentejovuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:agentejo:cockpit:*:*:*:*:*:*:*:*
Shodan: http.favicon.hash:688609340
Shodan: http.html:"cockpit"
FOFA: icon_hash=688609340
FOFA: body="cockpit"

Source: ProjectDiscovery

References

6