Cotonti Cotonti是Cotonti团队的一个内容管理系统。 Cotonti 1.0.0版本存在跨站请求伪造漏洞,该漏洞源于在Personal File Storage (PFS)模块文件上传操作中,未调用cot_check_xg()验证反CSRF令牌,可能导致远程攻击者引诱认证用户访问恶意页面,强制浏览器提交伪造的多部分请求,将任意文件上传至受害者PFS存储中,容易受到跨站请求伪造攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-55742 | 9.6 CRITICAL | Cotonti CSRF in admin.rights.php allows privilege escalation |
| CVE-2026-55741 | 8.8 HIGH | Cotonti CSRF in admin.config.php allows unauthorized configuration changes |
| CVE-2026-55746 | 7.6 HIGH | Cotonti stored XSS via PFS folder title |
| CVE-2026-55745 | 5.4 MEDIUM | Cotonti CSRF in PFS folder edit allows unauthorized folder modification |
No comments yet