Description
Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pages on trusted domains that redirect visitors to malicious sites for phishing attacks without administrative privileges.
Published: 2026-09-18
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Open Redirect with stored URL to arbitrary external sites
Action: Patch
AI Analysis

Impact

The vulnerability arises from the Cotonti CMS failing to validate URLs prefixed with redir: within page bodies. Authenticated users who can create or edit pages can embed a redirect to an arbitrary external host, which the CMS stores without sanitization. When visitors load the compromised page, they are silently sent to the attacker‑controlled domain, enabling phishing or other malicious campaigns. The weakness is a stored Open Redirect (CWE‑601), impacting the integrity of user navigation and the trustworthiness of the site.

Affected Systems

Cotonti CMS version 1.0.0. The vulnerability exists in all builds of this version across the distribution, as the source code host indicates. No other versions are affected according to the current CNA data.

Risk and Exploitability

The CVSS score is 5.1, which corresponds to a medium severity. The EPSS score is less than 1%, indicating a very low likelihood that publicly available exploits are in circulation. The vulnerability is not listed in CISA's KEV catalog. Exploitation requires internal authentication and permission to create or edit pages; thus, the attack vector is local rather than remote. An attacker with such privileges can craft and publish a page containing a malicious redir: URI, and anyone visiting that page would be redirected to the attacker’s chosen site.

Generated by OpenCVE AI on September 19, 2026 at 16:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply any official patch or newer release of Cotonti that removes the unsanitized redir: handling; check the vendor repository for an update.
  • If a patch is unavailable, disable or restrict the ability to create or edit pages for untrusted users, or remove the redir: prefix handler from page bodies.
  • Implement a whitelist of allowed redirect destinations or add server‑side validation to reject external URLs prefixed with redir:

Generated by OpenCVE AI on September 19, 2026 at 16:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Cotonti cotonti
Cotonti siena
Vendors & Products Cotonti cotonti
Cotonti siena

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pages on trusted domains that redirect visitors to malicious sites for phishing attacks without administrative privileges.
Title Cotonti through 1.0.0 Stored Open Redirect via Page redir: Prefix
First Time appeared Cotonti
Cotonti cotonti Siena
Weaknesses CWE-601
CPEs cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:*
Vendors & Products Cotonti
Cotonti cotonti Siena
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Cotonti Cotonti Cotonti Siena Siena
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:23:19.827Z

Reserved: 2026-09-18T19:39:41.099Z

Link: CVE-2026-93871

cve-icon Vulnrichment

Updated: 2026-09-21T16:34:16.343Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T20:17:35.097

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-93871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')