Cotonti 1.0.0 及更早版本中的搜索插件存在反射型跨站脚本(XSS)漏洞,其“highlight”参数未对 HTML 或 JavaScript 内容进行转义处理。攻击者可以构造包含恶意 JavaScript 代码的链接,通过该“highlight”参数注入脚本。当任何用户(包括管理员)打开该链接时,恶意脚本将在其浏览器中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100523 | 6.1 MEDIUM | Cotonti through 1.0.0 Open Redirect via message.php redirect parameter |
| CVE-2026-100522 | 6.1 MEDIUM | Cotonti through 1.0.0 Reflected XSS via message.php lng parameter |
| CVE-2026-100524 | 5.4 MEDIUM | Cotonti through 1.0.0 Cross-Site Request Forgery via Extensions Manager |
No comments yet