logo

CVE-2023-41564 cockpit-hq/cockpit

Package

Manager: composer
Name: cockpit-hq/cockpit
Vulnerable Version: >=0 <=2.6.3

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

EPSS: 0.20137 pctl0.95284

Details

Cockpit CMS arbitrary file upload vulnerability An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted `.shtml` file.

Metadata

Created: 2023-09-09T00:30:48Z
Modified: 2023-09-14T16:22:53Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-38vf-35cg-m73w/GHSA-38vf-35cg-m73w.json
CWE IDs: ["CWE-434"]
Alternative ID: GHSA-38vf-35cg-m73w
Finding: F027
Auto approve: 1