CVE-2020-35847

CRITICAL WAF: High
CVSS 9.8 Published: 2020-12-30
CWE-89

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.

WAF Coverage Analysis

SQL Injection High WAF Coverage

OWASP: A03:2021 Injection

942xxx - SQL Injection

Affected Software

VendorProductVersion
agentejocockpitup to 0.11.2

References

Back to CVE Database