.. / CVE-2020-14408

Exploit for Agentejo Cockpit 0.10.2 - Cross-Site Scripting (CVE-2020-14408)

Description:

Agentejo Cockpit 0.10.2 contains a reflected cross-site scripting vulnerability due to insufficient sanitization of the to parameter in the /auth/login route, which allows for injection of arbitrary JavaScript code into a web page’s content.

Nuclei Template

View the template here CVE-2020-14408.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-14408.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2020-14408
https://github.com/agentejo/cockpit/issues/1310
https://github.com/anonymous364872/Rapier_Tool
https://github.com/StarCrossPortal/scalpel
https://github.com/ARPSyndicate/kenzer-templates