Impact
The vulnerability arises from the Cotonti CMS failing to validate URLs prefixed with redir: within page bodies. Authenticated users who can create or edit pages can embed a redirect to an arbitrary external host, which the CMS stores without sanitization. When visitors load the compromised page, they are silently sent to the attacker‑controlled domain, enabling phishing or other malicious campaigns. The weakness is a stored Open Redirect (CWE‑601), impacting the integrity of user navigation and the trustworthiness of the site.
Affected Systems
Cotonti CMS version 1.0.0. The vulnerability exists in all builds of this version across the distribution, as the source code host indicates. No other versions are affected according to the current CNA data.
Risk and Exploitability
The CVSS score is 5.1, which corresponds to a medium severity. The EPSS score is less than 1%, indicating a very low likelihood that publicly available exploits are in circulation. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires internal authentication and permission to create or edit pages; thus, the attack vector is local rather than remote. An attacker with such privileges can craft and publish a page containing a malicious redir: URI, and anyone visiting that page would be redirected to the attacker’s chosen site.
OpenCVE Enrichment