Description
A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.
No analysis available yet.
Remediation
Vendor Solution
There is no reported solution at this time.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0697 | A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded. |
Github GHSA |
GHSA-q76r-7p4q-mqpw | Cockpit CMS Cross-Site Scripting vulnerability |
References
History
Tue, 04 Mar 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Agentejo
Agentejo cockpit |
|
| CPEs | cpe:2.3:a:agentejo:cockpit:2.7.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Agentejo
Agentejo cockpit |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T18:56:22.551Z
Reserved: 2024-02-29T07:51:12.605Z
Link: CVE-2024-2001
Updated: 2024-08-01T18:56:22.551Z
Status : Analyzed
Published: 2024-02-29T14:15:45.280
Modified: 2025-03-04T12:25:10.853
Link: CVE-2024-2001
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA