GHSA-7h6q-853g-5r6cMediumCVSS 4.3

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler,...

Published
September 18, 2026
Last Modified
September 18, 2026

🔗 CVE IDs covered (1)

📋 Description

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users. Attackers can craft malicious pages that auto-submit POST requests to modify stored rating data when visited by logged-in users.

🔗 References (7)