Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 26 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in the extensions manager that allows attackers to perform state-changing actions without anti-CSRF token validation. Attackers can craft links or embed images to force administrators to install, update, pause, or unpause extensions by tricking them into visiting a malicious page while authenticated. | |
| Title | Cotonti through 1.0.0 Cross-Site Request Forgery via Extensions Manager | |
| First Time appeared |
Cotonti
Cotonti cotonti Siena |
|
| Weaknesses | CWE-352 | |
| CPEs | cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cotonti
Cotonti cotonti Siena |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T00:59:24.986Z
Reserved: 2026-09-26T00:48:24.630Z
Link: CVE-2026-100524
No data.
Status : Deferred
Published: 2026-09-26T01:17:01.040
Modified: 2026-09-26T01:17:01.167
Link: CVE-2026-100524
No data.
OpenCVE Enrichment
No data.