Impact
The Cotonti 1.0.0 Comments plugin accepts a GET parameter named ci and forwards its value directly to PHP's unserialize() function without restricting allowed_classes. This flaw enables an unauthenticated attacker to supply a crafted serialized payload that instantiates arbitrary PHP objects. Through gadget chains embedded in the payload, an attacker can manipulate the database or execute arbitrary code on the host. The vulnerability is classified as CWE-502, which indicates insecure deserialization.
Affected Systems
The flaw is present in the Cotonti Comments plugin. The vendor field names the product as Cotonti, and the CPE string cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:* indicates the package, but no specific version is listed in the CNA data apart from the title mentioning 1.0.0. No other versions have been confirmed to contain this defect in the provided data.
Risk and Exploitability
The vulnerability has a CVSS score of 9.3, signifying critical impact when exploited. The EPSS score of less than 1% indicates a very low probability of exploitation at present, and the issue is not listed in the CISA KEV catalog. Attackers can reach the vulnerable endpoint without authentication, send a crafted ci parameter in a GET request, and potentially trigger gadget chain execution for code execution or database compromise. The overall risk remains high because of the severity, but the current likelihood of exploitation is low.
OpenCVE Enrichment