Versions of the package cockpit-hq/cockpit before 2.4.1 are vulnerable to Arbitrary File Upload where an attacker can use different extensions to bypass the upload filter.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view