CVE-2020-35848: SQL Injection
Published Dec 30, 2020
·Updated
Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.
Affected Software
1 affected component
Agentejo Cockpit<0.11.2
Remediation
Event History
Dec 30, 2020
CVE Published
via MITRE·12:39 AM
Data Sourced
via MITRE·12:39 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-35848.
2
What is the severity of CVE-2020-35848?
The severity of CVE-2020-35848 is critical with a CVSS score of 9.8.
3
What is the affected software for CVE-2020-35848?
The affected software for CVE-2020-35848 is Agentejo Cockpit before version 0.11.2.
4
How does CVE-2020-35848 work?
CVE-2020-35848 allows NoSQL injection via the Controller/Auth.php newpassword function in Agentejo Cockpit before version 0.11.2.
5
How can I fix CVE-2020-35848?
To fix CVE-2020-35848, update Agentejo Cockpit to version 0.11.2 or later.