Cotonti 1.0.0 及之前版本在评分插件的 AJAX 处理程序中未能正确验证反 CSRF(跨站请求伪造)令牌,攻击者可借此冒充已认证用户伪造评分。攻击者可以构造恶意页面,当已登录用户访问该页面时,页面会自动发送 POST 请求,从而篡改存储的评分数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93868 | 8.1 HIGH | Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG |
| CVE-2026-93872 | 7.5 HIGH | Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter |
| CVE-2026-93869 | 6.1 MEDIUM | Cotonti through 1.0.0 Open Redirect via Unanchored cot_url_check() Regex |
| CVE-2026-93871 | 5.4 MEDIUM | Cotonti through 1.0.0 Stored Open Redirect via Page redir: Prefix |
| CVE-2026-93873 | 4.3 MEDIUM | Cotonti through 1.0.0 Cross-Site Request Forgery in the Contact Plugin |
No comments yet