CVE-2020-10791: It-Novum Openitcockpit

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.

Affected products

  • It-Novum Openitcockpit: before 3.7.3 (fixed in 3.7.3)

Published 2020-03-25. Last modified 2026-06-17.