Sploitus

CVE-2024-2001

No indexed exploits for CVE-2024-2001 yet

A Cross-Site Scripting vulnerability in Cockpit CMS affecting version 2.7.0. This vulnerability could allow an authenticated user to upload an infected PDF file and store a malicious JavaScript payload to be executed when the file is uploaded.

Affected products
Cockpit Cms
Agentejo Cockpit
= 2.7.0
CVSS 3.1
5.5 MEDIUM
EPSS
0.3% (25th percentile)
Weakness
CWE-79
NVD status
Analyzed
Published
2024-02-29
Attack patterns
CAPEC-63

Fix

There is no reported solution at this time.

CVE-2024-2001 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2024-2001 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2024-2001 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.