Vulnerabilities > IT Novum > Openitcockpit > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-07-06 | CVE-2023-3520 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in It-Novum Openitcockpit Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6. | 4.6 |
2023-06-13 | CVE-2023-3218 | Race Condition within a Thread vulnerability in It-Novum Openitcockpit Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5. | 4.4 |
2020-03-25 | CVE-2020-10788 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in It-Novum Openitcockpit openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections. | 6.4 |
2020-03-25 | CVE-2020-10791 | Server-Side Request Forgery (SSRF) vulnerability in It-Novum Openitcockpit app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module. | 4.0 |
2020-03-20 | CVE-2020-10792 | Incorrect Default Permissions vulnerability in It-Novum Openitcockpit openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header. | 5.0 |
2019-12-31 | CVE-2019-10227 | Cross-site Scripting vulnerability in It-Novum Openitcockpit openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component. | 4.3 |
2019-08-23 | CVE-2019-15493 | Unspecified vulnerability in It-Novum Openitcockpit openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21. | 6.4 |
2019-08-23 | CVE-2019-15492 | Cross-site Scripting vulnerability in It-Novum Openitcockpit openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21. | 4.3 |
2019-08-23 | CVE-2019-15491 | Cross-Site Request Forgery (CSRF) vulnerability in It-Novum Openitcockpit openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21. | 6.8 |