Security for everyone

CVE-2020-35847 Scanner

Detects 'SQL Injection (SQLi)' vulnerability in Agentejo Cockpit affects v. before 0.11.2.

SCAN NOW

Short Info


Level

Critical

Type

Single Scan

Can be used by

Asset Owner

Estimated Time

15 sec

Scan only one

Url

Parent Category

CVE-2020-35847 Scanner Detail

Agentejo Cockpit is a web-based Content Management System (CMS) that enables website owners to manage their web content efficiently. This CMS is designed to simplify the website management process and provide website owners with a user-friendly interface to create, edit, and manage their web pages easily. Agentejo Cockpit is used by many businesses to manage their websites, and it has become increasingly popular in recent years.

Recently, a severe vulnerability was detected in Agentejo Cockpit, namely CVE-2020-35847. This vulnerability is a NoSQL injection that occurs in the Controller/Auth.php resetpassword function. Essentially, an attacker can exploit this vulnerability by injecting malicious code into the authentication process, leading to unauthorized access to the system.

The CVE-2020-35847 vulnerability can be very dangerous when exploited. It can allow attackers to gain access to sensitive information, such as passwords, users' email addresses, and other personal information. Hackers can use this information to launch further attacks on the system, leading to significant data breaches, financial loss, and client loss.

Thanks to the pro features of the securityforeveryone.com platform, it is now possible to learn about vulnerabilities in your digital assets easily and quickly. With this platform, you can scan your website for any vulnerabilities and receive instant alerts if any are detected. You can also evaluate your website’s security posture and receive recommended actions to mitigate any identified risks. By using this platform, you can rest assured that your website is secure and protected from attacks.

 

REFERENCES

cyber security services for everyone one. Free security tools, continuous vulnerability scanning and many more.
Try it yourself,
control security posture