CVE-2020-10792: It-Novum Openitcockpit

High severity, CVSS 7.5. EPSS: 1.9% chance of exploitation in the next 30 days.

openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.

Affected products

  • It-Novum Openitcockpit: up to and including 3.7.2

Published 2020-03-20. Last modified 2026-06-17.