Open Redirect Vulnerability in Cotonti Product by Cotonti
CVE-2026-100523

5.1MEDIUM

Key Information:

Vendor

Cotonti

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100523?

A critical open redirect vulnerability exists in Cotonti version 1.0.0 within the message.php file. This flaw occurs due to the lack of domain validation while base64-decoding the redirect parameter. Attackers can exploit this vulnerability by constructing malicious links containing encoded external URLs. When users click these links, they are redirected to arbitrary, potentially harmful sites, making them susceptible to phishing attacks that aim to steal sensitive information.

Affected Version(s)

Cotonti 0 <= 1.0.0

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.