Cotonti through 1.0.0 Open Redirect via message.php redirect parameter
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.1epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with encoded external URLs to redirect users to arbitrary sites via meta refresh tags for phishing attacks.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
Cotonti · CotontiReferences
https://github.com/Cotonti/Cotontihttps://github.com/Cotonti/Cotonti/blob/1.0.0/message.phphttps://github.com/Cotonti/Cotonti/blob/1.0.0/system/common.phphttps://github.com/Cotonti/Cotonti/issues/1907https://github.com/Cotonti/Cotonti/pull/1908https://www.vulncheck.com/advisories/cotonti-through-1.0.0-open-redirect-via-message-php-redirect-parameter