rootpwn

medium · CVSS v3 6.1 · CVSS v4 5.3

CVE-2026-93869

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect de…

Description

Cotonti through 1.0.0 contains an open redirect vulnerability in the cot_url_check() function that validates redirect destinations using a regular expression lacking an end-of-string anchor. Attackers can bypass the redirect guard by supplying hostnames beginning with the site domain to redirect users to attacker-controlled hosts through the ratings plugin or other redirect callers.

Scores

Severity
medium
CVSS v2
6.4
CVSS v3
6.1
CVSS v4
5.3
EPSS

← All CVEs