CVE-2020-35131: Agentejo Cockpit
Critical severity, CVSS 9.8. EPSS: 50.3% chance of exploitation in the next 30 days.
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.
Affected products
- Agentejo Cockpit: before 0.6.1 (fixed in 0.6.1)
Published 2021-01-08. Last modified 2026-06-17.