Junglewise Threat Intelligence

CVE-2026-55744: Cotonti CSRF in Personal File Storage module

CVE-2026-55744 · Severity: high · CVSS 8.1 · Published 2026-06-18

Technologies: cotonti/cotonti (Packagist), Cotonti. Vendors: Packagist, Cotonti.

Executive brief

Cotonti, a content management system, contains a security flaw in its Personal File Storage (PFS) module. This vulnerability allows an attacker to trick a logged-in user into unknowingly uploading files to the server by visiting a malicious website. This could lead to unauthorized file storage or potentially more severe server compromises if malicious scripts are uploaded.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in Cotonti 1.0.0 (specifically master branch commit f43f1fc3) within the Personal File Storage (PFS) module. The root cause is a failure to validate anti-CSRF tokens in the 'a=upload' action within modules/pfs/inc/pfs.main.php, whereas other actions like 'delete' correctly implement cot_check_xg() validation. An attacker can exploit this by luring an authenticated user to a malicious site that triggers a forged multipart POST request. This allows the attacker to upload arbitrary files to the victim's storage area without their consent.

Affected products

  • Cotonti Cotonti 1.0.0 (commit f43f1fc3)

Timeline

  • 2026-06-18: advisory: NVD publication date

References

Related threats