Impact
The vulnerability is a failure to validate anti-CSRF tokens in Cotonti's contact plugin, which permits attackers to embed a victim’s authenticated session within a forged form submission. The result is that the victim’s account appears to send an arbitrary message to the site administrator, potentially compromising the integrity of communications and enabling social‑engineering attacks.
Affected Systems
Cotonti Siena, version 1.0.0, where the contact plugin contains the flaw. All instances of this version deployed on web servers are susceptible until the plugin is patched or the application is updated.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS of less than 1% suggests exploitation is unlikely but still possible, especially in environments where authenticated users frequently use the contact form. The flaw is not listed in the CISA KEV catalog. Successful exploitation requires a victim to be authenticated and to unknowingly submit a crafted request from an attacker‑controlled page, which is a typical CSRF attack path.
OpenCVE Enrichment