Back

MEDIUM

Cross-Site Scripting vulnerability in Cockpit CMS

Published Feb 29, 2024

Description

A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.

Affected products

Remediation

Vendor solution

There is no reported solution at this time.

Metrics

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Feb 29, 2024
Updated Aug 1, 2024
Reserved Feb 29, 2024
CISA Vulnrichment
Updated Mar 1, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-Q76R-7P4Q-MQPW