Impact
The vulnerability in Cotonti prevents validation of anti‑CSRF tokens in the ratings plugin AJAX handler, enabling attackers to forge rating submissions on behalf of logged‑in users. By hosting a malicious page that auto‑submits POST requests to the ratings endpoint, an adversary can alter stored rating values, undermining the integrity of user‑generated content and potentially skewing reputation systems.
Affected Systems
This issue affects all installations of Cotonti up to and including version 1.0.0. The affected component is the ratings plugin’s AJAX handler. Subsequent releases beyond 1.0.0 contain the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is exploited via a web‑based attack that requires an authenticated user to visit a malicious page. Since the vulnerability is not listed in the CISA KEV catalog, there are no known mass‑scale exploits. Nonetheless, the impact on data integrity is significant for users who rely on accurate rating information.
OpenCVE Enrichment