Cockpit < 2.11.4 XSS

low Nessus Plugin ID 241956

Synopsis

Cockpit is affected by a cross site scripting vulnerability.

Description

The version of Cockpit running on the remote web server prior to 2.11.4. A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown processing of the file /system/users/save. The manipulation of the argument name/email leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 2.11.4 is able to address this issue.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Cockpit version 2.11.4 or later to address this issue

See Also

https://github.com/Cockpit-HQ/Cockpit/releases/tag/2.11.4

Plugin Details

Severity: Low

ID: 241956

File Name: cockpit_2_11_4.nasl

Version: 1.1

Type: remote

Published: 7/11/2025

Updated: 7/11/2025

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.9

CVSS v2

Risk Factor: Medium

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:N

CVSS Score Source: CVE-2025-7053

CVSS v3

Risk Factor: Low

Base Score: 3.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Vulnerability Information

CPE: cpe:/a:agentejo:cockpit

Required KB Items: installed_sw/Cockpit

Patch Publication Date: 7/3/2025

Vulnerability Publication Date: 7/3/2025

Reference Information

CVE: CVE-2025-7053

IAVA: 2025-A-0480