VDB
Sign up
CRITICAL9.8

GHSA-vpj8-xfqc-jcv9

Cockpit CMS contains an arbitrary file upload vulenrability

Quick fix

GHSA-vpj8-xfqc-jcv9 — cockpit-hq/cockpit: upgrade to the fixed version with the command below.

composer require cockpit-hq/cockpit:^2.7.0

Details

A vulnerability has been discovered in Agentejo Cockpit CMS v0.5.5 that consists in an arbitrary file upload in ‘/media/api’ parameter via post request. An attacker could upload files to the server, compromising the entire infrastructure.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/cockpit-hq/cockpit
Introduced in: 0Fixed in: 2.7.0
Fixcomposer require cockpit-hq/cockpit:^2.7.0

References