CVE-2020-35131: Agentejo Cockpit

Critical severity, CVSS 9.8. EPSS: 50.3% chance of exploitation in the next 30 days.

Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.

Affected products

  • Agentejo Cockpit: before 0.6.1 (fixed in 0.6.1)

Published 2021-01-08. Last modified 2026-06-17.