Executive brief
Cotonti, a content management system, contains a security flaw in its Personal File Storage (PFS) module. This vulnerability allows an attacker to trick a logged-in user into unknowingly uploading files to the server by visiting a malicious website. This could lead to unauthorized file storage or potentially more severe server compromises if malicious scripts are uploaded.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability exists in Cotonti 1.0.0 (specifically master branch commit f43f1fc3) within the Personal File Storage (PFS) module. The root cause is a failure to validate anti-CSRF tokens in the 'a=upload' action within modules/pfs/inc/pfs.main.php, whereas other actions like 'delete' correctly implement cot_check_xg() validation. An attacker can exploit this by luring an authenticated user to a malicious site that triggers a forged multipart POST request. This allows the attacker to upload arbitrary files to the victim's storage area without their consent.
Affected products
- Cotonti Cotonti 1.0.0 (commit f43f1fc3)
Timeline
- 2026-06-18: advisory: NVD publication date