Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100523— Cotonti through 1.0.0 Open Redirect via message.php redirect parameter

Quick assessment

Affected
Cotonti Cotonti
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cotonti 1.0.0 及之前版本中存在一个开放重定向漏洞,该漏洞位于 message.php 文件中,其重定向参数以 Base64 解码,但未进行域名验证。未认证的攻击者可以构造包含编码外部 URL 的恶意链接,通过 meta refresh 标签将用户重定向到任意网站,从而用于网络钓鱼攻击。

CVSS 6.1 · Medium EPSS 0.19% · P7
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100523

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cotonti through 1.0.0 Open Redirect via message.php redirect parameter
Source: CVE Program / CVE List V5
Vulnerability Description
Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with encoded external URLs to redirect users to arbitrary sites via meta refresh tags for phishing attacks.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
指向未可信站点的URL重定向(开放重定向)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Cotonti Cotonti 0 ~ 1.0.0 -

II. Public POCs for CVE-2026-100523

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100523

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-100523 (1)

Vendor Pages for CVE-2026-100523 (1)

Other References for CVE-2026-100523 (4)

Same Patch Batch · Cotonti · 2026-09-26 · 4 CVEs total

CVE-2026-100522 6.1 MEDIUM Cotonti through 1.0.0 Reflected XSS via message.php lng parameter
CVE-2026-100521 6.1 MEDIUM Cotonti through 1.0.0 Reflected XSS via search highlight parameter
CVE-2026-100524 5.4 MEDIUM Cotonti through 1.0.0 Cross-Site Request Forgery via Extensions Manager

IV. Related Vulnerabilities

V. Comments for CVE-2026-100523

No comments yet


Leave a comment