Vulnerabilities > IT Novum > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-07-06 CVE-2023-3520 Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in It-Novum Openitcockpit
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6.
network
low complexity
it-novum CWE-614
4.6
2023-06-13 CVE-2023-3218 Race Condition within a Thread vulnerability in It-Novum Openitcockpit
Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5.
network
high complexity
it-novum CWE-366
4.4
2020-03-25 CVE-2020-10788 Use of a Broken or Risky Cryptographic Algorithm vulnerability in It-Novum Openitcockpit
openITCOCKPIT before 3.7.3 uses the 1fea123e07f730f76e661bced33a94152378611e API key rather than generating a random API Key for WebSocket connections.
network
low complexity
it-novum CWE-327
6.4
2020-03-25 CVE-2020-10791 Server-Side Request Forgery (SSRF) vulnerability in It-Novum Openitcockpit
app/Plugin/GrafanaModule/Controller/GrafanaConfigurationController.php in openITCOCKPIT before 3.7.3 allows remote authenticated users to trigger outbound TCP requests (aka SSRF) via the Test Connection feature (aka testGrafanaConnection) of the Grafana Module.
network
low complexity
it-novum CWE-918
4.0
2020-03-20 CVE-2020-10792 Incorrect Default Permissions vulnerability in It-Novum Openitcockpit
openITCOCKPIT through 3.7.2 allows remote attackers to configure the self::DEVELOPMENT or self::STAGING option by placing a hostname containing "dev" or "staging" in the HTTP Host header.
network
low complexity
it-novum CWE-276
5.0
2019-12-31 CVE-2019-10227 Cross-site Scripting vulnerability in It-Novum Openitcockpit
openITCOCKPIT before 3.7.1 has reflected XSS in the 404-not-found component.
network
it-novum CWE-79
4.3
2019-08-23 CVE-2019-15493 Unspecified vulnerability in It-Novum Openitcockpit
openITCOCKPIT before 3.7.1 allows deletion of files, aka RVID 4-445b21.
network
low complexity
it-novum
6.4
2019-08-23 CVE-2019-15492 Cross-site Scripting vulnerability in It-Novum Openitcockpit
openITCOCKPIT before 3.7.1 has reflected XSS, aka RVID 3-445b21.
network
it-novum CWE-79
4.3
2019-08-23 CVE-2019-15491 Cross-Site Request Forgery (CSRF) vulnerability in It-Novum Openitcockpit
openITCOCKPIT before 3.7.1 has CSRF, aka RVID 2-445b21.
network
it-novum CWE-352
6.8