S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-35847 Scanner

CVE-2020-35847 scanner - SQL Injection (SQLi) vulnerability in Agentejo Cockpit

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.7k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-35847
9.8
CVSS

Agentejo Cockpit before 0.11.2 allows NoSQL injection via the Controller/Auth.php resetpassword function.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Agentejo Cockpit is a web-based Content Management System (CMS) that enables website owners to manage their web content efficiently. This CMS is designed to simplify the website management process and provide website owners with a user-friendly interface to create, edit, and manage their web pages easily. Agentejo Cockpit is used by many businesses to manage their websites, and it has become increasingly popular in recent years.

Recently, a severe vulnerability was detected in Agentejo Cockpit, namely CVE-2020-35847. This vulnerability is a NoSQL injection that occurs in the Controller/Auth.php resetpassword function. Essentially, an attacker can exploit this vulnerability by injecting malicious code into the authentication process, leading to unauthorized access to the system.

The CVE-2020-35847 vulnerability can be very dangerous when exploited. It can allow attackers to gain access to sensitive information, such as passwords, users' email addresses, and other personal information. Hackers can use this information to launch further attacks on the system, leading to significant data breaches, financial loss, and client loss.

Thanks to the pro features of the s4e.io platform, it is now possible to learn about vulnerabilities in your digital assets easily and quickly. With this platform, you can scan your website for any vulnerabilities and receive instant alerts if any are detected. You can also evaluate your website’s security posture and receive recommended actions to mitigate any identified risks. By using this platform, you can rest assured that your website is secure and protected from attacks.

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners and administrators need to take some precautions. Here are a few tips to ensure the safety of your website:

  • Install the latest version of Agentejo Cockpit and patch the vulnerability.
  • Use strong passwords and enable two-factor authentication.
  • Regularly audit your system for vulnerabilities and patch them promptly.
  • Employ a reliable web application firewall to help prevent attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.