CVE-2026-55742
Severity CVSS v4.0:
CRITICAL
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
18/06/2026
Last modified:
22/06/2026
Description
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update action ('a=update') modifies group access rights (including via cot_auth_add_group) without calling cot_check_xg() to validate the anti-CSRF token. A remote attacker who lures an authenticated administrator into visiting a malicious page can force the browser to submit a forged request that grants elevated permissions to an attacker-controlled group, escalating privileges to administrator. Because Cotonti administrators can modify templates and configuration, this can be further leveraged toward remote code execution.
Impact
Base Score 4.0
9.40
Severity 4.0
CRITICAL
Base Score 3.x
9.60
Severity 3.x
CRITICAL



