Executive brief
The Cotonti CMS Comments plugin contains a critical vulnerability in how it handles user input from the "ci" GET parameter. The plugin passes this untrusted data directly to PHP's unserialize() function without restricting which classes can be instantiated, allowing attackers to remotely inject malicious serialized objects. An attacker can exploit this to execute arbitrary PHP code or manipulate the database without needing to authenticate first.
Technical details
The vulnerability is a PHP object injection flaw caused by unsafe deserialization in the Comments plugin. The ci GET parameter is passed to unserialize() without the allowed_classes restriction, permitting attackers to craft malicious serialized payloads containing arbitrary PHP object instances. Since the deserialization occurs without authentication checks, any unauthenticated attacker can trigger the vulnerability via a simple HTTP request. By crafting payloads that exploit PHP magic methods (__wakeup, __destruct, __toString), attackers can leverage existing gadget chains in the application or its dependencies to achieve remote code execution or database manipulation. No patch availability information is currently documented in the advisory.
Affected products
- Cotonti Comments 1.0.0
Timeline
- 2026-09-15: disclosed
- 2026-09-15: advisory