CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-100523

CVE-2026-100523. CVSS base score 6.1 (MEDIUM, Vendor/CNA). EPSS 0.00188 (percentile 0.07549), scored 2026-10-04.

Affected technology

Cotonti · 0 through 1.0.0
Cotonti

Description’s affected range: through 1.0.0

Component: Not specified by the source
File: message.php, system/common.php

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · Active user interaction

What an attacker can do

Unauthenticated attackers can craft malicious links with encoded external URLs to redirect users to arbitrary sites via meta refresh tags for phishing attacks. Vendor/CNA’s CVSS 4.0 assessment rates confidentiality, integrity and availability impact as none.

Published

CWE
CWE-601
CCR priority
24.4 /100 (P4)
CVSS
6.1 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N · Vendor/CNA
EPSS
0.00188 · percentile 0.07549 · 2026-10-04
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-100523.html