CVE-2020-35846: SQL Injection
Published Dec 30, 2020
·Updated
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php check function.
Affected Software
1 affected component
Agentejo Cockpit<0.11.2
Remediation
Event History
Dec 30, 2020
CVE Published
via MITRE·12:39 AM
Data Sourced
via MITRE·12:39 AM
Description
Frequently Asked Questions
1
What is CVE-2020-35846?
CVE-2020-35846 is a vulnerability in Agentejo Cockpit before 0.11.2 that allows NoSQL injection via the Controller/Auth.php check function.
2
What is the severity of CVE-2020-35846?
CVE-2020-35846 has a severity rating of 9.8 (critical).
3
How does CVE-2020-35846 affect Agentejo Cockpit?
CVE-2020-35846 affects Agentejo Cockpit versions up to and excluding 0.11.2.
4
How can the NoSQL injection vulnerability in Agentejo Cockpit be exploited?
The NoSQL injection vulnerability in Agentejo Cockpit can be exploited via the Controller/Auth.php check function.
5
Is there a fix for CVE-2020-35846?
Yes, the fix for CVE-2020-35846 is available in Agentejo Cockpit version 0.11.2.