PT-2026-57003 · Unknown · Cotonti Siena

·

CVE-2026-58144

·

Published

2026-07-09

·

Updated

2026-07-10

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Cotonti Siena versions prior to 0.9.27
Description Authenticated users with PFS access can perform a stored cross-site scripting attack. This occurs when malicious HTML is supplied via the ntitle parameter, which is processed through the TXT filter in the 'pfs.main.php' endpoint. An attacker can create a folder with a crafted title containing script tags that are stored unescaped in the database. These scripts then execute in the browser of any user who views the folder listing, including administrators.
Recommendations Update to a version newer than 0.9.26.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58144

Affected Products

Cotonti Siena