CVE-2026-100523
Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with encoded external URLs to redirect users to arbitrary sites via meta refresh tags for phishing attacks.
Weakness
Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with encoded external URLs to redirect users to arbitrary sites via meta refresh tags for phishing attacks.
References
- https://github.com/Cotonti/Cotonti
- https://github.com/Cotonti/Cotonti/blob/1.0.0/message.php
- https://github.com/Cotonti/Cotonti/blob/1.0.0/system/common.php
- https://github.com/Cotonti/Cotonti/issues/1907
- https://github.com/Cotonti/Cotonti/pull/1908
- https://www.vulncheck.com/advisories/cotonti-through-1.0.0-open-redirect-via-message-php-redirect-parameter
Find the bug before an attacker does.
Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.