CVE-2018-9856: Kotti Project Kotti

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Kotti before 1.3.2 and 2.x before 2.0.0b2 has CSRF in the local roles implementation, as demonstrated by triggering a permission change via a /admin-document/@@share request.

Affected products

  • Kotti Project Kotti: before 1.3.2 (fixed in 1.3.2); version 2.0.0 only; version 2.0.0b1 only

Published 2018-04-09. Last modified 2026-06-17.