Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with encoded external URLs to redirect users to arbitrary sites via meta refresh tags for phishing attacks.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 26 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with encoded external URLs to redirect users to arbitrary sites via meta refresh tags for phishing attacks. | |
| Title | Cotonti through 1.0.0 Open Redirect via message.php redirect parameter | |
| First Time appeared |
Cotonti
Cotonti cotonti Siena |
|
| Weaknesses | CWE-601 | |
| CPEs | cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cotonti
Cotonti cotonti Siena |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T00:59:24.331Z
Reserved: 2026-09-26T00:48:22.887Z
Link: CVE-2026-100523
No data.
Status : Deferred
Published: 2026-09-26T01:17:00.870
Modified: 2026-09-26T01:17:00.993
Link: CVE-2026-100523
No data.
OpenCVE Enrichment
Updated: 2026-09-26T02:45:02Z
Weaknesses