medium · CVSS v3 4.3 · CVSS v4 5.3
CVE-2026-93870
Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge…
Description
Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users. Attackers can craft malicious pages that auto-submit POST requests to modify stored rating data when visited by logged-in users.
Scores
- Severity
- medium
- CVSS v2
- 5
- CVSS v3
- 4.3
- CVSS v4
- 5.3
- EPSS
- —