Vendor
low
advisory
Stored Cross-Site Scripting in Agentejo Cockpit CMS
1 rule 2 TTPs 1 CVEAgentejo Cockpit CMS versions up to 2.6.3 contain a stored XSS vulnerability via the asset upload endpoint, allowing attackers to execute arbitrary JavaScript by uploading and accessing malicious .shtml files.
Cockpit CMS
web-security
xss
cms
1r
2t
1c
critical
advisory
Cockpit CMS Authenticated Remote Code Execution via Code Injection
2 rules 1 TTP 1 CVECockpit CMS is vulnerable to authenticated remote code execution via PHP code injection in the /cockpit/collections/save_collection endpoint, enabling attackers with collection management privileges to execute arbitrary commands on the server.
Cockpit CMS
rce
code-injection
cockpit-cms
2r
1t
1c