Cotonti Siena 0.9.19 contains a stored cross-site scripting vulnerability in the admin configuration panel's site title parameter. Attackers can inject malicious JavaScript code through the 'maintitle' parameter to execute scripts when administrators view the page.
References
| Link | Resource |
|---|---|
| https://cotonti.com | Broken Link |
| https://www.cotonti.com/download/ | Product |
| https://www.exploit-db.com/exploits/50016 | Exploit |
| https://www.vulncheck.com/advisories/cotonti-siena-maintitle-stored-cross-site-scripting | Third Party Advisory |
| https://www.exploit-db.com/exploits/50016 | Exploit |
Configurations
History
No history.
Information
Published : 2026-01-16 00:16
Updated : 2026-02-02 16:16
NVD link : CVE-2021-47808
Mitre link : CVE-2021-47808
CVE.ORG link : CVE-2021-47808
JSON object : View
Products Affected
cotonti
- cotonti_siena
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
