Impact
The vulnerability arises from the cot_url_check() function in Cotonti versions up to 1.0.0, where the validator employs a regular expression missing the end-of-string anchor. This oversight lets an attacker craft hostnames beginning with the legitimate site domain, causing the function to accept them as legitimate destinations. The effect is an open redirect that can carry users from the victim site to arbitrary, attacker-controlled URLs. The weakness aligns with CWE‑601, which addresses open redirect flaws that undermine user trust and may be used for phishing or session hijacking.
Affected Systems
The defect is present in Cotonti 1.0.0, affecting the core application and redirect callers such as the ratings plugin. The vendor is the Cotonti project and the affected release is explicitly version 1.0.0; no other releases are listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the medium severity range, reflecting a non-critical threat but still meaningful in contexts where redirects are exposed to untrusted input. The EPSS score is less than 1%, so the likelihood of active exploitation is currently low and the vulnerability is not listed in CISA KEV. Attackers would most likely trigger the flaw by directing a user through the web application to a crafted redirect URL, leveraging the missing anchor in the regex. Because the vulnerability resides in an open plugin, an application update or disabling the plug-in mitigates the risk.
OpenCVE Enrichment