Cotonti Siena
cpe:2.3:a:cotonti:cotonti_siena:*:*:*:*:*:*:*
- 0.9.19
A stored cross-site scripting vulnerability has been identified in Cotonti Siena version 0.9.19. The issue resides in the admin configuration panel, specifically within the site title parameter. This vulnerability allows attackers to inject malicious JavaScript code through the 'maintitle' parameter, which is executed when administrators view the page.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the page.
To reproduce this vulnerability, log into the Cotonti admin panel and navigate to the 'Configuration' tab. Inject a script payload into the 'maintitle' parameter of the site title configuration. After updating the configuration, the injected script will execute when the home page is viewed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.