GHSA-wx35-cv59-9gwr
Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
Details
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.main.php, the file upload action ('a=upload') processes uploaded files without calling cot_check_xg() to validate the anti-CSRF token, even though sibling actions such as 'delete' (line 272) do. A remote attacker who lures an authenticated user into visiting a malicious page can force the browser to submit a forged multipart request that uploads arbitrary files into the victim's PFS storage.
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for cotonti/cotonti (composer). Pin to a known-safe version or switch to an alternative.