Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly escaped before output in the confirmation dialog. Unauthenticated attackers can craft malicious links with script payloads in the lng parameter to execute arbitrary JavaScript in victim browser sessions.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 26 Sep 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cotonti cotonti
|
|
| Vendors & Products |
Cotonti cotonti
|
Sat, 26 Sep 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cotonti through 1.0.0 contains a reflected cross-site scripting vulnerability in message.php where the lng parameter is not properly escaped before output in the confirmation dialog. Unauthenticated attackers can craft malicious links with script payloads in the lng parameter to execute arbitrary JavaScript in victim browser sessions. | |
| Title | Cotonti through 1.0.0 Reflected XSS via message.php lng parameter | |
| First Time appeared |
Cotonti
Cotonti cotonti Siena |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cotonti
Cotonti cotonti Siena |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-26T00:59:23.634Z
Reserved: 2026-09-26T00:48:21.175Z
Link: CVE-2026-100522
No data.
Status : Deferred
Published: 2026-09-26T01:17:00.700
Modified: 2026-09-26T01:17:00.823
Link: CVE-2026-100522
No data.
OpenCVE Enrichment
Updated: 2026-09-26T09:00:13Z
Weaknesses