Impact
Cotonti versions before 1.0.0 contain a CSRF flaw in the admin.users.php script that permits an attacker to delete user groups without passing a verified anti‑CSRF token. An attacker can embed a crafted link into an email, page, or any resource that, when clicked by an authenticated administrator, causes the target group and its permissions to be removed. This results in loss of access control for legitimate users that rely on the deleted group, and can weaken the overall authorization model of the application.
Affected Systems
The flaw exists in Cotonti 1.0.0 and earlier releases. System administrators should determine whether their installation uses Cotonti 1.0.0 or any older snapshot. The CPE identifier cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:* identifies the affected package.
Risk and Exploitability
The CVSS base score of 5.3 indicates a medium severity. No EPSS score is available, so current exploitation likelihood is unclear. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is CSRF, requiring an authenticated administrator’s session; an attacker can trigger the deletion from a victim’s browser once the admin is logged in.
OpenCVE Enrichment