S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-35848 Scanner

CVE-2020-35848 scanner - SQL Injection (SQLi) vulnerability in Agentejo Cockpit

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-35848
9.8
CVSS

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php newpassword function.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Agentejo Cockpit is a content management system used by developers to manage their websites and digital assets. The platform allows users to easily create and edit website content without requiring advanced technical knowledge. It is popular due to its intuitive user interface and flexible customization options. This product is widely used by developers of varying skill levels, from beginners to advanced professionals.

Recently, a security vulnerability was detected in Agentejo Cockpit, identified as CVE-2020-35848. This vulnerability is a NoSQL injection that occurs through the Controller/Auth.php newpassword function. An attacker could exploit this flaw to access sensitive information on the target system or even execute malicious code, which could lead to data theft, website hijacking, and other security incidents.

If an attacker exploits the vulnerability in Agentejo Cockpit, they could gain unauthorized access to sensitive data on the system. They could steal user information, admin credentials, or even personal data from customers. This could lead to identity theft, fraud, and other serious consequences. The vulnerability could also affect website functionality or even allow hackers to take full control of the site, causing significant harm to the brand reputation and business operations of the targeted organization.

In conclusion, this CVE-2020-35848 vulnerability in Agentejo Cockpit can cause significant damage to businesses and their digital assets. Take preventive measures to protect against such vulnerabilities through the aforementioned precautions. Using a secure vulnerability scanning tool like s4e.io can help detect and remediate vulnerabilities, thereby keeping digital assets and websites safe and secure.

 

REFERENCES

Solution Advice

To protect against NoSQL injection vulnerabilities like CVE-2020-35848, users of Agentejo Cockpit should take the following precautions:

  • Keep the system updated with the latest security patches and software versions.
  • Use a robust password for their accounts and avoid using the same password across multiple platforms.
  • Limit access to sensitive data within the system and use role-based access controls to restrict permissions.
  • Use content security policies to limit third-party scripts and protect against cross-site scripting (XSS) attacks.
  • Regularly test system security with reliable vulnerability scanning tools such as SecurityForEveryone.com.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-35848 scanner - SQL Injection (SQLi) vulnerability in Agentejo Cockpit S4E