Critical severity9.8NVD Advisory· Published Jan 8, 2021· Updated Jun 17, 2026
CVE-2020-35131
CVE-2020-35131
Description
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestreset URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Cockpit/Cockpitdescription
- Range: <0.6.1
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/49390nvdExploitThird Party AdvisoryVDB Entry
- github.com/agentejo/cockpit/commits/next/lib/MongoLite/Database.phpnvdThird Party Advisory
- github.com/agentejo/cockpit/releases/tag/0.6.1nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.