Cross-Site Request Forgery in Cotonti Affects User Group Management
CVE-2026-101093
5.3MEDIUM
What is CVE-2026-101093?
Cotonti, up to version 1.0.0, is susceptible to a cross-site request forgery (CSRF) vulnerability found in the admin.users.php file. This flaw permits attackers to execute unauthorized actions, specifically enabling the deletion of user groups without proper token verification. By ingeniously crafting malicious links or web pages, an attacker can trick authenticated administrators into unwittingly executing the deletion of custom user groups, along with their associated permissions, while leveraging the administrator's active session. Organizations utilizing Cotonti should promptly implement the necessary security measures to mitigate this risk.
Affected Version(s)
Cotonti 0 <= 1.0.0
