Impact
Cotonti versions up to and including 1.0.0 allow an unauthenticated attacker to trigger a redirection by manipulating the redirect parameter in message.php. The application base64‑decodes the parameter and injects the resulting URL into a meta refresh tag without validating the domain, creating an open redirect. This flaw can be used for phishing or other social‑engineering attacks by redirecting unsuspecting users to malicious sites, thereby compromising user trust and potentially facilitating credential theft.
Affected Systems
The vulnerability exists in Cotonti version 1.0.0; any deployment running this release is impacted unless a later fix has been applied.
Risk and Exploitability
The CVSS score of 5.1 indicates a low‑to‑moderate risk for exploitation. The EPSS score is not reported, and the flaw is not listed in CISA’s KEV catalog, suggesting limited known exploitation. Nonetheless, the issue is navigable by unauthenticated users through crafted URLs, making it an attractive vector for phishing campaigns.
OpenCVE Enrichment