Impact
Cotonti 1.0.0 includes a flaw in the comments plugin where the base64‑decoded "cb" parameter is passed directly to PHP's unserialize() function without restricting the classes that can be instantiated. This grants attackers who have comment write permissions the ability to create arbitrary PHP objects. By carefully crafting these objects, an attacker can leverage gadget chains to perform actions such as arbitrary file writes or code execution, thereby compromising the confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects Cottoni CMS version 1.0.0, specifically the comments plugin EditAction controller. Users of this version who have registered comment‑write privileges are exposed, including any administrator or power user accounts that have the ability to edit comments.
Risk and Exploitability
The CVSS score of 7.7 indicates significant severity, while the EPSS score of less than 1% suggests a low probability of exploitation as of the latest data. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Because exploitation requires a legitimate user with comment‑write access to invoke the EditAction endpoint, the attack vector is likely through the web application with an authenticated session, rather than over an unauthenticated remote interface. Successful exploitation could allow an attacker to execute code or modify critical files on the server hosting the Cottoni instance.
OpenCVE Enrichment