Skip to main content

CVE-2020-35131 cockpit: registerCriteriaFunction in lib/MongoLite/Database.php allows for a Remote Command Execution via custom php code injection

Publication Date 2021-01-08
Severity Low
Type Cross-Site Request Forgery
Affected PHP Versions
Fixed Product Versions

CVE Details

Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI. A flaw was found in cockpit. An attacker is able to inject custom PHP code and achieve remote command execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Recommendations

555