Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function of the Auth controller.
View the template here CVE-2020-35847.yaml
echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-35847.yaml
References: