Description
A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.
No analysis available yet.
Remediation
Vendor Solution
Update to version 2.7.0.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1810 | A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure. |
Github GHSA |
GHSA-vpj8-xfqc-jcv9 | Cockpit CMS contains an arbitrary file upload vulenrability |
References
History
Fri, 27 Jun 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Agentejo
Agentejo cockpit |
|
| CPEs | cpe:2.3:a:agentejo:cockpit:0.5.5:*:*:*:*:*:*:* | |
| Vendors & Products |
Agentejo
Agentejo cockpit |
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T20:55:10.120Z
Reserved: 2024-05-13T08:15:39.916Z
Link: CVE-2024-4825
Updated: 2024-08-01T20:55:10.120Z
Status : Analyzed
Published: 2024-05-14T15:45:16.483
Modified: 2025-06-27T15:04:13.027
Link: CVE-2024-4825
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA