Vulnerabilities
Vulnerable Software
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6.
CVSS Score
4.3
EPSS Score
0.0
Published
2023-07-06
Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5.
CVSS Score
6.5
EPSS Score
0.0
Published
2023-06-13
openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections.
CVSS Score
9.1
EPSS Score
0.003
Published
2020-03-25
openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php.
CVSS Score
9.8
EPSS Score
0.006
Published
2020-03-25
openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.
CVSS Score
5.4
EPSS Score
0.004
Published
2020-03-25
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.
CVSS Score
6.5
EPSS Score
0.001
Published
2020-03-25
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
CVSS Score
7.5
EPSS Score
0.005
Published
2020-03-20
openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.
CVSS Score
6.1
EPSS Score
0.004
Published
2019-12-31
openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.
CVSS Score
9.8
EPSS Score
0.005
Published
2019-08-23
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
CVSS Score
8.8
EPSS Score
0.001
Published
2019-08-23


Contact Us

Shodan ® - All rights reserved