PT-2026-95702 · Cotonti · Cotonti
CVE-2026-93871
·
Published
2026-09-18
·
Updated
2026-09-27
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cotonti versions prior to 1.0.1
Description
Authenticated users with page creation or edit permissions can store redirects to arbitrary external hosts because the software fails to validate redirect destinations in page bodies prefixed with
redir:. This allows attackers to create pages on trusted domains that redirect visitors to malicious sites for phishing purposes without requiring administrative privileges.Recommendations
Update Cotonti to a version newer than 1.0.0.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cotonti