Open Redirect Vulnerability in Cotonti by Cotonti Team
CVE-2026-93869
5.3MEDIUM
What is CVE-2026-93869?
Cotonti, versions up to 1.0.0, possesses an open redirect vulnerability in the cot_url_check() function. This issue stems from an insufficient validation process of redirect destinations due to a regular expression that lacks an end-of-string anchor. Exploiting this vulnerability, attackers can construct malicious URLs starting with the site domain, enabling unauthorized redirection of users to their own hostile web pages via the ratings plugin or other redirect mechanisms. Proper sanitization and validation measures are crucial to mitigate this security risk.
Affected Version(s)
Cotonti 0 <= 1.0.0
