CVE-2018-11471
Published May 25, 2018Cockpit 0.5.5 has XSS via a collection, form, or region.
Vendor/product archive
2 CVEs tagged to getcockpit / cockpit — 1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
Cockpit 0.5.5 has XSS via a collection, form, or region.
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts v…