CVE-2020-35847: SQL Injection
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-35847.
What is the title of this vulnerability?
The title of this vulnerability is 'Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword func…'
What is the severity of CVE-2020-35847?
The severity of CVE-2020-35847 is critical with a severity value of 9.8.
What software version is affected by CVE-2020-35847?
Agentejo Cockpit versions up to and excluding 0.11.2 are affected by this vulnerability.
How can NoSQL injection be exploited in Agentejo Cockpit before 0.11.2?
NoSQL injection can be exploited via the Controller/Auth.php resetpassword function in Agentejo Cockpit before version 0.11.2.
Are there any references available for CVE-2020-35847?
Yes, there are references available for CVE-2020-35847. You can find them at the following links: [link1](http://packetstormsecurity.com/files/162282/Cockpit-CMS-0.11.1-NoSQL-Injection-Remote-Command-Execution.html), [link2](http://packetstormsecurity.com/files/163762/Cockpit-CMS-0.11.1-NoSQL-Injection.html), [link3](https://getcockpit.com/).
What is the CWE (Common Weakness Enumeration) ID for this vulnerability?
The CWE ID for this vulnerability is 89.