Loading market data...
← Back to CVE feed

CVE-2026-93870

MEDIUM CVSS 4.3 View on NVD ↗

Description

Cotonti through 1.0.0 fails to validate anti-CSRF tokens in the ratings plugin AJAX handler, allowing attackers to forge ratings on behalf of authenticated users. Attackers can craft malicious pages that auto-submit POST requests to modify stored rating data when visited by logged-in users.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Published: Sep 18, 2026 20:17 UTC Modified: Sep 18, 2026 20:17 UTC