CVE-2020-14408: Agentejo Cockpit
Medium severity, CVSS 6.1. EPSS: 3% chance of exploitation in the next 30 days.
An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.
Affected products
- Agentejo Cockpit: version 0.10.2 only
Published 2020-06-17. Last modified 2026-06-17.