Impact
Cotonti Siena 0.9.26 contains a stored XSS flaw in the PFS module where the ntitle parameter is processed through the TXT filter without escaping, allowing authenticated users to inject arbitrary script tags. When a folder is created with a malicious title, the script is stored unescaped in the database and executed in the browser of any user who views the folder listing, including administrators. The arbitrary scripts executed in a user's browser may enable client‑side attacks (inference).
Affected Systems
Cotonti Siena 0.9.26 and all earlier releases are affected. The CVE description explicitly states that “0.9.26 and earlier” contain the flaw, indicating that any version equal to or older than 0.9.26 is vulnerable.
Risk and Exploitability
The vulnerability scores a CVSS of 5.1, indicating moderate severity. Because the attack requires authenticated access with PFS privileges, exploitation is constrained to users who can log in and create folders; therefore the attack vector is considered remote authenticated. The EPSS score is < 1%, indicating a very low probability of exploitation, and the issue is not listed in the CISA KEV catalog, suggesting limited public exploitation activity but still presenting a risk to organizations relying on Cotonti Siena for content management.
OpenCVE Enrichment