VDB
KO
CRITICAL 9.6

GHSA-7g3p-35vc-mgjr

Cotonti: Cross-Site Request Forgery in the administration rights handler

Details

Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update action ('a=update') modifies group access rights (including via cot_auth_add_group) without calling cot_check_xg() to validate the anti-CSRF token. A remote attacker who lures an authenticated administrator into visiting a malicious page can force the browser to submit a forged request that grants elevated permissions to an attacker-controlled group, escalating privileges to administrator. Because Cotonti administrators can modify templates and configuration, this can be further leveraged toward remote code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist / cotonti/cotonti
Introduced in: 0

No fixed version published yet for cotonti/cotonti (composer). Pin to a known-safe version or switch to an alternative.

References