Impact
A cross‑site request forgery flaw (CWE‑352) exists in Cotonti Siena 0.9.26 and all earlier releases. An unauthenticated attacker can entice a logged‑in administrator into submitting a forged POST request to the admin.php configuration update endpoint, which never performs the framework’s CSRF validation. The attacker can set the configuration parameter pfsfilecheck to 0, disabling the PFS module’s file‑extension whitelist and allowing any user with PFS upload permissions to upload and execute arbitrary PHP files on the web server, ultimately giving the attacker full remote code execution capabilities.
Affected Systems
The vulnerability affects the Cotonti Siena content management system in version 0.9.26 and all earlier releases. No other vendors or product lines are impacted according to the available data.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating high severity, while the EPSS score is < 1%, reflecting a very low exploitation probability; the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an active administrator session and the attacker to lure or trick the admin into submitting the forged request, typically via social engineering or phishing. Once the configuration change is applied, an attacker with PFS upload privileges can drop malicious PHP files, resulting in complete compromise of the affected web server.
OpenCVE Enrichment