Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2020-35846] From 0 to RCE: Cockpit CMS

Summary

A vulnerability chain in open-source CMS Cockpit: unauthenticated NoSQL injections (CVE-2020-35846) allow username extraction through blind $eq and $regex techniques, escalating to take over any user account and finally to remote code execution.
Published
Collected

original ↗

Related coverage

back