Cotonti Cotonti是Cotonti团队的一个内容管理系统。 Cotonti 1.0.0版本存在跨站请求伪造漏洞,该漏洞源于在Personal File Storage (PFS)模块中,文件夹更新操作未调用cot_check_xg()验证反CSRF令牌,可能导致远程攻击者诱使认证用户访问恶意页面,从而修改受害者的文件夹元数据(包括将私有文件夹设为公开)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55742 | 9.6 CRITICAL | Cotonti CSRF in admin.rights.php allows privilege escalation |
| CVE-2026-55741 | 8.8 HIGH | Cotonti CSRF in admin.config.php allows unauthorized configuration changes |
| CVE-2026-55744 | 8.1 HIGH | Cotonti CSRF in PFS allows forced arbitrary file upload |
| CVE-2026-55746 | 7.6 HIGH | Cotonti stored XSS via PFS folder title |
No comments yet