CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100523

MEDIUMCVSS 6.1NVD feed

Published 26 September 2026 · tracked since 26 September 2026

Description

Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with encoded external URLs to redirect users to arbitrary sites via meta refresh tags for phishing at

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100523 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100523

MEDIUMCVSS 6.1NVD feed

Published 26 September 2026 · tracked since 26 September 2026

Description

Cotonti through 1.0.0 contains an open redirect vulnerability in message.php that base64-decodes the redirect parameter without domain validation. Unauthenticated attackers can craft malicious links with encoded external URLs to redirect users to arbitrary sites via meta refresh tags for phishing at

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]