VYPR
Medium severity6.1NVD Advisory· Published Jun 17, 2020· Updated Jun 17, 2026

CVE-2020-14408

CVE-2020-14408

Description

An issue was discovered in Agentejo Cockpit 0.10.2. Insufficient sanitization of the to parameter in the /auth/login route allows for injection of arbitrary JavaScript code into a web page's content, creating a Reflected XSS attack vector.

Affected products

3
  • Agentejo/Cockpitcpe-rescue3 versions
    (expand)+ 2 more
    • (no CPE)
    • cpe:2.3:a:agentejo:cockpit:0.10.2:*:*:*:*:*:*:*
    • (no CPE)range: =0.10.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.