Cotonti(版本直至 1.0.0)在扩展管理器中存在跨站请求伪造(CSRF)漏洞,允许攻击者在未经 CSRF 令牌验证的情况下执行状态变更操作。攻击者可构造恶意链接或嵌入恶意图片,诱使已认证的管理员访问恶意页面,从而强制其安装、更新、暂停或取消暂停扩展。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100523 | 6.1 MEDIUM | Cotonti through 1.0.0 Open Redirect via message.php redirect parameter |
| CVE-2026-100522 | 6.1 MEDIUM | Cotonti through 1.0.0 Reflected XSS via message.php lng parameter |
| CVE-2026-100521 | 6.1 MEDIUM | Cotonti through 1.0.0 Reflected XSS via search highlight parameter |
No comments yet