Reflected XSS Vulnerability in Agentejo Cockpit Web Application
CVE-2020-14408
6.1MEDIUM
What is CVE-2020-14408?
In Agentejo Cockpit version 0.10.2, a significant flaw exists due to inadequate sanitization of input parameters in the /auth/login route. This weakness enables an attacker to inject arbitrary JavaScript code into web page content, creating a vector for Reflected XSS attacks that can compromise the security and integrity of user sessions.
