Cotonti 1.0.0 及之前版本未能对以 "redir:" 前缀标识的页面正文中的重定向目标进行有效验证,导致拥有页面创建或编辑权限的已认证用户能够存储指向任意外部主机的重定向链接。攻击者可借此在受信任的域名上创建此类页面,使访问者被重定向至恶意网站,从而实施钓鱼攻击,且无需管理员权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93868 | 8.1 HIGH | Cotonti through 1.0.0 Predictable Password Recovery Token via Weak PRNG |
| CVE-2026-93872 | 7.5 HIGH | Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter |
| CVE-2026-93869 | 6.1 MEDIUM | Cotonti through 1.0.0 Open Redirect via Unanchored cot_url_check() Regex |
| CVE-2026-93870 | 4.3 MEDIUM | Cotonti through 1.0.0 Cross-Site Request Forgery in the Ratings Plugin AJAX Handler |
| CVE-2026-93873 | 4.3 MEDIUM | Cotonti through 1.0.0 Cross-Site Request Forgery in the Contact Plugin |
No comments yet