.. / CVE-2020-35847

Exploit for Agentejo Cockpit <0.11.2 - NoSQL Injection (CVE-2020-35847)

Description:

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function of the Auth controller.

Nuclei Template

View the template here CVE-2020-35847.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-35847.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2020-35847
https://github.com/agentejo/cockpit/commit/33e7199575631ba1f74cba6b16b10c820bec59af
https://swarm.ptsecurity.com/rce-cockpit-cms/
https://github.com/agentejo/cockpit/commit/2a385af8d80ed60d40d386ed813c1039db00c466
https://getcockpit.com/