Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.
Recent assessments:
h00die at May 31, 2021 12:11pm UTC reported:
Similar to CVE-2020-35846, this is a noSQL injection using the var_dump
function to dump all memory for the password reset tokens. The vulnerability is within the /auth/requestreset
When combined with CVE-2020-35846, its possible to dump all users and their password reset tokens. With this, a successful password reset of the admin user is possible. Once logged in, using the /accounts/find
API, a command injection vulnerability is achieved although there was no CVE assigned to this.
Assessed Attacker Value: 0
Assessed Attacker Value: 0Assessed Attacker Value: 0
packetstormsecurity.com/files/162282/Cockpit-CMS-0.11.1-NoSQL-Injection-Remote-Command-Execution.html
packetstormsecurity.com/files/163762/Cockpit-CMS-0.11.1-NoSQL-Injection.html
cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35847
getcockpit.com/
github.com/agentejo/cockpit/commit/2a385af8d80ed60d40d386ed813c1039db00c466
github.com/agentejo/cockpit/commit/33e7199575631ba1f74cba6b16b10c820bec59af
github.com/agentejo/cockpit/commit/79fc9631ffa29146e3124ceaf99879b92e1ef24b