Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hp3v-wp32-953h | Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module |
Wed, 24 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cotonti
Cotonti cotonti |
|
| Vendors & Products |
Cotonti
Cotonti cotonti |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.editfolder.php, the folder update action ('a=update') updates folder metadata (title, description, public/gallery flags) without calling cot_check_xg() to validate the anti-CSRF token. A remote attacker who lures an authenticated user into visiting a malicious page can force the browser to submit a forged request that modifies the victim's folder metadata, including making a private folder public. | |
| Title | Cotonti CSRF in PFS folder edit allows unauthorized folder modification | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-06-18T12:53:11.134Z
Reserved: 2026-06-17T12:59:17.621Z
Link: CVE-2026-55745
Updated: 2026-06-18T12:53:06.421Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-24T20:42:07Z
Github GHSA