Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hp3v-wp32-953h | Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module |
Mon, 10 Aug 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.editfolder.php, the folder update action ('a=update') updates folder metadata (title, description, public/gallery flags) without calling cot_check_xg() to validate the anti-CSRF token. A remote attacker who lures an authenticated user into visiting a malicious page can force the browser to submit a forged request that modifies the victim's folder metadata, including making a private folder public. | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.editfolder.php, the folder update action ('a=update') updates folder metadata (title, description, public/gallery flags) without calling cot_check_xg to validate the anti-CSRF token. |
| Title | Cotonti - CSRF in PFS Folder Edit Allows Unauthorized Folder Modification | Cotonti CSRF in PFS folder edit allows unauthorized folder modification |
Mon, 10 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cotonti CSRF in PFS folder edit allows unauthorized folder modification | Cotonti - CSRF in PFS Folder Edit Allows Unauthorized Folder Modification |
Wed, 24 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cotonti
Cotonti cotonti |
|
| Vendors & Products |
Cotonti
Cotonti cotonti |
Thu, 18 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.editfolder.php, the folder update action ('a=update') updates folder metadata (title, description, public/gallery flags) without calling cot_check_xg() to validate the anti-CSRF token. A remote attacker who lures an authenticated user into visiting a malicious page can force the browser to submit a forged request that modifies the victim's folder metadata, including making a private folder public. | |
| Title | Cotonti CSRF in PFS folder edit allows unauthorized folder modification | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-10T11:44:29.461Z
Reserved: 2026-06-17T12:59:17.621Z
Link: CVE-2026-55745
Updated: 2026-06-18T12:53:06.421Z
Status : Deferred
Published: 2026-06-18T08:16:34.337
Modified: 2026-08-10T12:17:19.213
Link: CVE-2026-55745
No data.
OpenCVE Enrichment
Updated: 2026-08-10T23:45:04Z
Github GHSA