Impact
Cotonti through version 1.0.0 contains a reflected cross‑site scripting vulnerability in its search plugin. The highlight parameter accepts unsanitized input, allowing attackers to embed malicious JavaScript that executes in a visitor’s browser when the link is opened. This flaw permits code execution under the context of the victim, potentially exposing session cookies, defacing content, or redirecting to phishing sites.
Affected Systems
All installations of Cotonti using the default search plugin up to and including version 1.0.0 are affected. The vulnerability is present in the plugin files "search.header.php" and "search.page.first.php", and affects any deployment that enables the highlight feature of the search module. Administrators or any user clicking the crafted link will trigger the flaw.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity, and the EPSS score is not available, so current exploitation probability is uncertain. The issue is not listed in the CISA KEV catalog, meaning no widely disclosed exploits are known. The attack vector is web‑based and requires only a crafted URL; no authentication or privileged access is needed. The exposure primarily threatens confidentiality and integrity in the scope of affected user sessions.
OpenCVE Enrichment