Impact
Cotonti versions up to 1.0.0 lack anti‑CSRF token validation in the extensions manager. This allows an attacker who can trick an authenticated administrator into visiting a crafted link or embedding an image to trigger state‑changing actions such as installing, updating, pausing, or unpausing extensions. The resulting unauthorized configuration changes compromise the integrity of the system and could enable further malicious activity.
Affected Systems
Cotonti Cotonti up to and including version 1.0.0 is impacted. No further version specifics are listed in the data provided.
Risk and Exploitability
The vulnerability receives a CVSS score of 5.3, indicating moderate severity. Exploitation requires the attacker to entice a legitimate admin to visit a malicious page, a common social‑engineering scenario, and there is no publicly available exploit code or tool. Because the EPSS score is not available and the issue is not listed in CISA KEV, the likelihood of widespread exploitation remains low, but the potential impact to administrative control warrants prompt attention.
OpenCVE Enrichment