Agentejo Cockpit prior to 0.12.0 is vulnerable to NoSQL Injection via the newpassword method of the Auth controller, which is responsible for displaying the user password reset form.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view