Impact
The vulnerability is a reflected cross‑site scripting flaw in Cotonti version 1.0.0, where the language parameter in message.php is not adequately escaped before being echoed back in a confirmation dialog. An attacker can embed arbitrary JavaScript within that parameter, causing it to execute in the browsers of any user who opens the malicious link. The impact is confined to client‑side compromise, enabling credential theft, session hijacking, or defacement within the context of the affected application.
Affected Systems
Cotonti, version 1.0.0, is the only documented affected release. Users running this version of the Cotonti Siena stack are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate severity, with no network restriction but a requirement for user interaction. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation yet. Exploitation requires an unauthenticated attacker to craft a link with a malicious language value and persuade a victim to click it, making it a typical phishing or social engineering vector.
OpenCVE Enrichment