Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2023-3520
Disclosure Date: July 06, 2023 (last updated October 08, 2023)
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6.
0
Attacker Value
Unknown
CVE-2023-36663
Disclosure Date: June 25, 2023 (last updated October 08, 2023)
it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface.
0
Attacker Value
Unknown
CVE-2023-3218
Disclosure Date: June 13, 2023 (last updated October 08, 2023)
Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5.
0
Attacker Value
Unknown
CVE-2020-10788
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections.
0
Attacker Value
Unknown
CVE-2020-10791
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.
0
Attacker Value
Unknown
CVE-2020-10789
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell metacharacters that are mishandled on an su command line in app/Lib/SudoMessageInterface.php.
0
Attacker Value
Unknown
CVE-2020-10790
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
openITCOCKPIT before 3.7.3 has unnecessary files (such as Lodash files) under the web root, which leads to XSS.
0
Attacker Value
Unknown
CVE-2020-10792
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
0
Attacker Value
Unknown
CVE-2019-15494
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
openITCOCKPIT before 3.7.1 allows SSRF, aka RVID 5-445b21.
0
Attacker Value
Unknown
CVE-2019-15492
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.
0