CVE-2020-10791: It-Novum Openitcockpit
Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.
Affected products
- It-Novum Openitcockpit: before 3.7.3 (fixed in 3.7.3)
Published 2020-03-25. Last modified 2026-06-17.