PT-2026-95703 · Cotonti · Cotonti
CVE-2026-93872
·
Published
2026-09-18
·
Updated
2026-09-22
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Cotonti version 1.0.0
Description
In the comments plugin EditAction, the software passes the base64-decoded
cb parameter to the unserialize() function without restricting allowed classes. This allows registered users with comment write permissions to instantiate arbitrary PHP objects, which may lead to file write or remote code execution through gadget chains (sequences of existing code fragments that can be leveraged to achieve an unintended goal).Recommendations
Update Cotonti version 1.0.0 to a version where the
unserialize() function in the comments plugin EditAction is properly restricted or replaced. As a temporary mitigation, restrict comment write permissions for registered users.Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cotonti