Description
Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft malicious links or pages that trick authenticated administrators into deleting custom groups and their associated permissions by riding the administrator's session.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Privilege Modification via unauthorized group deletion
Action: Patch
AI Analysis

Impact

Cotonti versions before 1.0.0 contain a CSRF flaw in the admin.users.php script that permits an attacker to delete user groups without passing a verified anti‑CSRF token. An attacker can embed a crafted link into an email, page, or any resource that, when clicked by an authenticated administrator, causes the target group and its permissions to be removed. This results in loss of access control for legitimate users that rely on the deleted group, and can weaken the overall authorization model of the application.

Affected Systems

The flaw exists in Cotonti 1.0.0 and earlier releases. System administrators should determine whether their installation uses Cotonti 1.0.0 or any older snapshot. The CPE identifier cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:* identifies the affected package.

Risk and Exploitability

The CVSS base score of 5.3 indicates a medium severity. No EPSS score is available, so current exploitation likelihood is unclear. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is CSRF, requiring an authenticated administrator’s session; an attacker can trigger the deletion from a victim’s browser once the admin is logged in.

Generated by OpenCVE AI on September 28, 2026 at 23:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Cotonti to a version newer than 1.0.0 where the CSRF check has been added to admin.users.php.
  • If an immediate upgrade is not possible, block external access to the group‑deletion endpoint or add a validated anti‑CSRF token to the link or form used for deletion.
  • Restrict administrative access to a dedicated, isolated network zone and enforce multi‑factor authentication to reduce the risk of session theft.
  • Conduct a review of all pages that link directly to the group‑deletion URL to ensure no other CSRF‑prone paths remain.

Generated by OpenCVE AI on September 28, 2026 at 23:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
First Time appeared Cotonti siena
Vendors & Products Cotonti siena

Mon, 28 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft malicious links or pages that trick authenticated administrators into deleting custom groups and their associated permissions by riding the administrator's session.
Title Cotonti through 1.0.0 Cross-Site Request Forgery via User Group Deletion
First Time appeared Cotonti
Cotonti cotonti Siena
Weaknesses CWE-352
CPEs cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:*
Vendors & Products Cotonti
Cotonti cotonti Siena
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Cotonti Cotonti Siena Siena
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T22:00:18.495Z

Reserved: 2026-09-27T20:29:07.433Z

Link: CVE-2026-101093

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-28T22:17:30.810

Modified: 2026-09-28T22:17:30.980

Link: CVE-2026-101093

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T01:00:11Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)