CVE-2020-35848 describes a critical NoSQL injection vulnerability in Agentejo Cockpit versions prior to 0.11.2, specifically within the Controller/Auth.php newpassword function. This flaw carries a CVSS score of 9.8 (CRITICAL) due to its network-exploitable nature, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. While not currently on CISA's KEV catalog or showing active exploitation, public exploit code exists (e.g., ExploitDB, Nuclei templates), and its high EPSS score indicates a significant likelihood of future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.11.2CPE matchmatch criteria | cpe:2.3:a:agentejo:cockpit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.