CVE-2026-93871 Details
Description
Cotonti through 1.0.0 fails to validate redirect destinations in page bodies prefixed with redir:, allowing authenticated users with page creation or edit permissions to store redirects to arbitrary external hosts. Attackers can craft pages on trusted domains that redirect visitors to malicious sites for phishing attacks without administrative privileges.
A stored open redirect vulnerability has been identified in Cotonti versions through 1.0.0. The issue arises because the application fails to properly validate redirect URLs in page bodies that begin with 'redir:'. This flaw allows authenticated users with permission to create or edit pages to insert redirects to any external website. As a result, attackers could potentially use trusted pages to redirect visitors to malicious sites for phishing purposes, all without needing administrative rights.
Users are advised to update to Cotonti version 1.0.1 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 18, 2026CISA-ADP
Assessed Sep 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Cotonti/Cotonti | [email protected] | Vendor |
| https://github.com/Cotonti/Cotonti/blob/1.0.0/modules/page/inc/page.main.php | [email protected] | Source CodeVendor |
| https://github.com/Cotonti/Cotonti/issues/1893 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/Cotonti/Cotonti/pull/1901 | [email protected] | Source CodeVendor |
| https://www.vulncheck.com/advisories/cotonti-through-1.0.0-stored-open-redirect-via-page-redir-prefix | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cotonti | <= 1.0.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | CISA-ADP |
| Sep 18, 2026 | New CVE Received | [email protected] |
Volerion