PT-2026-57002 · Unknown · Cotonti Siena

·

CVE-2026-58143

·

Published

2026-07-09

·

Updated

2026-07-10

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cotonti Siena versions prior to 0.9.27
Description A cross-site request forgery (CSRF) issue exists where unauthenticated attackers can modify administrator configurations. This occurs because the admin.php config update handler does not invoke the application's CSRF validation function. By tricking a logged-in administrator into submitting a forged POST request, an attacker can set the pfsfilecheck variable to 0. This action disables the Perfect Forward Secrecy (PFS) module's file extension whitelist, allowing any user with PFS access to upload and execute arbitrary PHP files on the server.
Recommendations Update Cotonti Siena to a version newer than 0.9.26. Restrict access to the admin.php config update handler to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58143

Affected Products

Cotonti Siena