{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aagentejocockpit/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:agentejo:cockpit:*:*:*:*:*:*:*:*","cpe:2.3:a:agentejo:cockpit:2.6.3:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":6.1,"id":"CVE-2023-41564"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cockpit CMS (\u003c= 2.6.3)"],"_cs_severities":["low"],"_cs_tags":["web-security","xss","cms"],"_cs_type":"advisory","_cs_vendors":["Agentejo"],"content_html":"\u003cp\u003eAgentejo Cockpit CMS versions up to and including 2.6.3 are susceptible to a stored Cross-Site Scripting (XSS) vulnerability. The flaw exists within the file upload functionality of the CMS, specifically located at the \u003ccode\u003eassets/upload\u003c/code\u003e endpoint. An attacker with the ability to upload files can bypass the application's extension blacklisting mechanism to upload a file with an \u003ccode\u003e.shtml\u003c/code\u003e extension containing embedded malicious JavaScript. When a user subsequently accesses the URL of the uploaded file, the browser executes the embedded script within the context of the CMS application. This vulnerability is documented as CVE-2023-41564 and presents a risk of session hijacking, credential theft, or unauthorized actions performed on behalf of authenticated users.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the target Cockpit CMS instance with a user account authorized to upload assets.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious \u003ccode\u003e.shtml\u003c/code\u003e file containing a JavaScript payload.\u003c/li\u003e\n\u003cli\u003eAttacker sends a POST request to the \u003ccode\u003e/assets/upload\u003c/code\u003e endpoint containing the crafted \u003ccode\u003e.shtml\u003c/code\u003e file.\u003c/li\u003e\n\u003cli\u003eThe server-side logic fails to properly sanitize or block the \u003ccode\u003e.shtml\u003c/code\u003e extension despite its blacklisting logic for other dangerous file types.\u003c/li\u003e\n\u003cli\u003eThe server saves the file to the assets directory and returns the file path to the attacker.\u003c/li\u003e\n\u003cli\u003eAttacker distributes the URL of the uploaded \u003ccode\u003e.shtml\u003c/code\u003e asset to a target user, often through social engineering or by placing it where users are likely to interact with it.\u003c/li\u003e\n\u003cli\u003eTarget user visits the URL, causing the web browser to render the file and execute the malicious JavaScript payload in the user's session context.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the execution of arbitrary JavaScript in the context of a victim's session, potentially leading to unauthorized data access, session token theft, or malicious actions within the CMS. The vulnerability affects all Cockpit CMS installations up to version 2.6.3.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize updating all instances of Cockpit CMS to a version beyond 2.6.3 that addresses the insecure file upload validation logic. As an immediate mitigation, implement strict ingress filtering at the Web Application Firewall (WAF) to block requests to \u003ccode\u003e/assets/upload\u003c/code\u003e that attempt to upload files with non-standard or dangerous extensions, specifically targeting \u003ccode\u003e.shtml\u003c/code\u003e and other server-side parsing extensions. Additionally, ensure that the server's MIME type handling and file upload policies are configured to enforce a whitelist-only approach for permitted file types, rather than relying solely on blacklists.\u003c/p\u003e\n","date_modified":"2026-08-31T13:04:26Z","date_published":"2026-08-31T13:04:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2023-41564/","summary":"Agentejo Cockpit CMS versions up to 2.6.3 contain a stored XSS vulnerability via the asset upload endpoint, allowing attackers to execute arbitrary JavaScript by uploading and accessing malicious .shtml files.","title":"Stored Cross-Site Scripting in Agentejo Cockpit CMS","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2023-41564/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:agentejo:cockpit:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}