Description
Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.
Published: 2026-09-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Cotonti 1.0.0 includes a flaw in the comments plugin where the base64‑decoded "cb" parameter is passed directly to PHP's unserialize() function without restricting the classes that can be instantiated. This grants attackers who have comment write permissions the ability to create arbitrary PHP objects. By carefully crafting these objects, an attacker can leverage gadget chains to perform actions such as arbitrary file writes or code execution, thereby compromising the confidentiality, integrity, and availability of the affected system.

Affected Systems

The vulnerability affects Cottoni CMS version 1.0.0, specifically the comments plugin EditAction controller. Users of this version who have registered comment‑write privileges are exposed, including any administrator or power user accounts that have the ability to edit comments.

Risk and Exploitability

The CVSS score of 7.7 indicates significant severity, while the EPSS score of less than 1% suggests a low probability of exploitation as of the latest data. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Because exploitation requires a legitimate user with comment‑write access to invoke the EditAction endpoint, the attack vector is likely through the web application with an authenticated session, rather than over an unauthenticated remote interface. Successful exploitation could allow an attacker to execute code or modify critical files on the server hosting the Cottoni instance.

Generated by OpenCVE AI on September 19, 2026 at 16:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch from the Cotonti pull request that limits allowed classes in unserialize or upgrade to the latest stable release where the issue is resolved.
  • Disable or tightly restrict comment‑write permissions for all non‑trusted users, applying the least privilege principle until a fix is deployed.
  • If a patch is unavailable, implement an input validation layer that rejects or sanitizes base64‑encoded payloads for the "cb" parameter, or configure the application to use PHP’s allowed_classes restriction when calling unserialize.

Generated by OpenCVE AI on September 19, 2026 at 16:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Cotonti cotonti
Cotonti siena
Vendors & Products Cotonti cotonti
Cotonti siena

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Cotonti 1.0.0 passes the base64-decoded cb parameter to unserialize() without allowed_classes restriction in the comments plugin EditAction. Registered users with comment write permissions can instantiate arbitrary PHP objects and potentially achieve file write or code execution through gadget chains.
Title Cotonti 1.0.0 PHP Object Injection via Comments Plugin Edit Action cb Parameter
First Time appeared Cotonti
Cotonti cotonti Siena
Weaknesses CWE-502
CPEs cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:*
Vendors & Products Cotonti
Cotonti cotonti Siena
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Cotonti Cotonti Cotonti Siena Siena
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:23:20.808Z

Reserved: 2026-09-18T19:39:42.007Z

Link: CVE-2026-93872

cve-icon Vulnrichment

Updated: 2026-09-21T16:42:43.076Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T20:17:35.250

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-93872

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:45:16Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data