Cross-Site Request Forgery Vulnerability in Cotonti Extensions Manager
CVE-2026-100524

5.3MEDIUM

Key Information:

Vendor

Cotonti

Status
Vendor
CVE Published:
26 September 2026

What is CVE-2026-100524?

The extensions manager in Cotonti up to version 1.0.0 is susceptible to cross-site request forgery attacks, allowing unauthorized actions to be executed without proper anti-CSRF token validation. Attackers may create deceptive links or embed harmful images to manipulate authenticated administrators into installing, updating, or altering the state of extensions. This security flaw exploits the trust established between the user and the application, potentially compromising the integrity and security of the system.

Affected Version(s)

Cotonti 0 <= 1.0.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.