CVE-2026-100523 MEDIUM

CVE-2026-100523: Cotonti through 1.0.0 Open Redirect via message.php redirect parameter

Vendor Cotonti
Product Cotonti
Weakness CWE-601 · Open redirect
Published September 26, 2026
Last update September 26, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction —
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with encoded external URLs to redirect users to arbitrary sites via meta refresh tags for phishing attacks.

Key dates

02Disclosure timeline

September 26, 2026 CVE published

Related vulnerabilities

04Related CVE