CVE-2020-10792: It-Novum Openitcockpit
High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
Affected products
- It-Novum Openitcockpit: up to and including 3.7.2
Published 2020-03-20. Last modified 2026-06-17.