[CVE-2020-35846] From 0 to RCE: Cockpit CMS
swarm.ptsecurity.com | research | CVE-2020-35846 | #rce | #vulnerability-research | #cve | #nosql-injection | #cms
Summary
A vulnerability chain in open-source CMS Cockpit: unauthenticated NoSQL injections (CVE-2020-35846) allow username extraction through blind $eq and $regex techniques, escalating to take over any user account and finally to remote code execution.
- Published
- Collected
Skip to content