{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acotonticotonti/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cotonti:cotonti:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-93872"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Cotonti (1.0.0)"],"_cs_severities":["high"],"_cs_tags":["web-application","deserialization","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Cotonti"],"content_html":"\u003cp\u003eCotonti version 1.0.0 is affected by an insecure deserialization vulnerability within its comments plugin, specifically within the EditAction function. The application accepts a 'cb' parameter from the user, which is base64-decoded and passed directly to the PHP \u003ccode\u003eunserialize()\u003c/code\u003e function without implementing \u003ccode\u003eallowed_classes\u003c/code\u003e restrictions. This design flaw allows authenticated users who possess comment write permissions to inject and instantiate arbitrary PHP objects. If a suitable gadget chain exists within the application's codebase or dependencies, an attacker can leverage this primitive to achieve file write operations or remote code execution. This vulnerability represents a significant risk to the integrity and availability of the platform, as it permits authenticated low-privileged users to elevate their impact to server-side code execution.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for potential remote code execution and arbitrary file writes on servers running Cotonti 1.0.0. An attacker must have a registered account with comment write permissions to exploit this flaw. Successful exploitation can lead to a full system compromise, data exfiltration, or unauthorized modification of the website's backend infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should focus on identifying abnormal HTTP traffic patterns associated with the 'cb' parameter in comment-related requests.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor web server logs for requests to the comments plugin that contain base64-encoded strings within the 'cb' parameter.\u003c/li\u003e\n\u003cli\u003eAudit PHP code and dependencies for vulnerable classes or gadgets that could be combined with \u003ccode\u003eunserialize()\u003c/code\u003e to facilitate exploit chains.\u003c/li\u003e\n\u003cli\u003eRestrict application permissions where possible to limit the number of users capable of interacting with the vulnerable EditAction functionality.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T22:11:22Z","date_published":"2026-09-18T22:11:22Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cotonti-unserialize-rce/","summary":"Cotonti version 1.0.0 contains an insecure deserialization vulnerability in the comments plugin allowing authenticated users to trigger object injection and potential remote code execution.","title":"Insecure Deserialization in Cotonti Comments Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-cotonti-unserialize-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:cotonti:cotonti:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}