Open Redirect Vulnerability in Cotonti Product by Cotonti
CVE-2026-100523
5.1MEDIUM
What is CVE-2026-100523?
A critical open redirect vulnerability exists in Cotonti version 1.0.0 within the message.php file. This flaw occurs due to the lack of domain validation while base64-decoding the redirect parameter. Attackers can exploit this vulnerability by constructing malicious links containing encoded external URLs. When users click these links, they are redirected to arbitrary, potentially harmful sites, making them susceptible to phishing attacks that aim to steal sensitive information.
Affected Version(s)
Cotonti 0 <= 1.0.0
