Unrestricted Upload of File with Dangerous Type vulnerability on Cockpit CMS from Agentejo
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 0.7%
exploitation probability
0.7%top 48% of all CVEs
observed exploitation
nono source reports it
A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Agentejo · Cockpit CMS