Количество 2
Количество 2
CVE-2026-55745
Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.editfolder.php, the folder update action ('a=update') updates folder metadata (title, description, public/gallery flags) without calling cot_check_xg to validate the anti-CSRF token.
GHSA-hp3v-wp32-953h
Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55745 Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.editfolder.php, the folder update action ('a=update') updates folder metadata (title, description, public/gallery flags) without calling cot_check_xg to validate the anti-CSRF token. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
GHSA-hp3v-wp32-953h Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module | CVSS3: 5.4 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу