Cotonti 1.0.0 及之前版本中存在一个开放重定向漏洞,该漏洞位于 message.php 文件中,其重定向参数以 Base64 解码,但未进行域名验证。未认证的攻击者可以构造包含编码外部 URL 的恶意链接,通过 meta refresh 标签将用户重定向到任意网站,从而用于网络钓鱼攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100522 | 6.1 MEDIUM | Cotonti through 1.0.0 Reflected XSS via message.php lng parameter |
| CVE-2026-100521 | 6.1 MEDIUM | Cotonti through 1.0.0 Reflected XSS via search highlight parameter |
| CVE-2026-100524 | 5.4 MEDIUM | Cotonti through 1.0.0 Cross-Site Request Forgery via Extensions Manager |
No comments yet