CVE-2026-101093 Details
Description
Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft malicious links or pages that trick authenticated administrators into deleting custom groups and their associated permissions by riding the administrator's session.
A cross-site request forgery (CSRF) vulnerability has been identified in Cotonti versions through 1.0.0, specifically within the admin.users.php file. This vulnerability allows attackers to delete user groups without proper token verification. By crafting malicious links or pages, attackers can deceive authenticated administrators into removing custom groups and their associated permissions, exploiting the administrator's session.
Users can update to Cotonti version 1.0.1 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026CISA-ADP
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Cotonti/Cotonti | [email protected] | Source CodeVendor |
| https://github.com/Cotonti/Cotonti/blob/1.0.0/system/admin/admin.users.php#L136-L140 | [email protected] | Source CodeVendor |
| https://github.com/Cotonti/Cotonti/issues/1907#issuecomment-5845691148 | [email protected] | Issue TrackingTechnical AnalysisVendor |
| https://github.com/Cotonti/Cotonti/pull/1908 | [email protected] | Issue TrackingVendor |
| https://www.vulncheck.com/advisories/cotonti-through-1.0.0-cross-site-request-forgery-via-user-group-deletion | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cotonti | <= 1.0.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | CVE Modified | CISA-ADP |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion