Stored Open Redirect in Cotonti Affects User Trust
CVE-2026-93871
5.1MEDIUM
What is CVE-2026-93871?
Cotonti versions prior to 1.0.0 contain a vulnerability that fails to properly validate redirect destinations for page bodies prefixed with 'redir:'. This flaw allows authenticated users with permissions to create or edit pages to store redirects leading to arbitrary external sites. As a result, attackers can craft seemingly credible pages on trusted domains that redirect unsuspecting visitors to malicious sites designed for phishing attacks, posing a significant risk to user data and trust.
Affected Version(s)
Cotonti 0 <= 1.0.0
