Количество 2
Количество 2
CVE-2026-55746
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage (PFS) module. A folder title (pff_title) is imported with the 'TXT' filter, which does not strip or encode HTML (the tag check in cot_import is disabled), so an authenticated user can store HTML/JavaScript in a folder title.
GHSA-86hp-hf3j-3m8r
Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55746 Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage (PFS) module. A folder title (pff_title) is imported with the 'TXT' filter, which does not strip or encode HTML (the tag check in cot_import is disabled), so an authenticated user can store HTML/JavaScript in a folder title. | CVSS3: 7.6 | 0% Низкий | 3 месяца назад | |
GHSA-86hp-hf3j-3m8r Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module | CVSS3: 7.6 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу