1.
swarm.ptsecurity.com | research | | original ↗ | #rce | #vulnerability-research | #cve | #nosql-injection
A vulnerability chain in open-source CMS Cockpit: unauthenticated NoSQL injections (CVE-2020-35846) allow username extraction through blind $eq and $regex techniques, escalating to take over any user account and finally to remote code execution.
Skip to content