Medium severity5.5NVD Advisory· Published Feb 29, 2024· Updated Jun 17, 2026
CVE-2024-2001
CVE-2024-2001
Description
A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- ghsa-coords
- Cockpit CMS/Cockpit CMSv5Range: 2.7.0
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-q76r-7p4q-mqpwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-2001ghsaADVISORY
- www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerability-cockpit-cmsnvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.