Tag
high
advisory
Command Injection in Cockpit CMS FFmpeg Integration
1 rule 1 TTP 1 CVECockpit CMS versions 2.14.0 and prior are vulnerable to authenticated command injection via malicious filenames processed by the FFmpeg integration.
Cockpit CMS
web-application-vulnerability
remote-code-execution
injection
cockpit-cms
1r
1t
1c
critical
advisory
Cockpit CMS Authenticated Remote Code Execution via Code Injection
2 rules 1 TTP 1 CVECockpit CMS is vulnerable to authenticated remote code execution via PHP code injection in the /cockpit/collections/save_collection endpoint, enabling attackers with collection management privileges to execute arbitrary commands on the server.
Cockpit CMS
rce
code-injection
cockpit-cms
2r
1t
1c