PT-2026-97328 · Redaxo · Redaxo
CVE-2026-63000
·
Published
2026-09-23
·
Updated
2026-09-29
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
REDAXO versions prior to 5.21.2
Description
REDAXO is a PHP-based content management system. The
rex api install package update() function within the install addon fails to override the requiresCsrfProtection() method, which defaults to false in the base class. This allows an unauthenticated attacker to perform a Cross-Site Request Forgery (CSRF) attack, where a logged-in administrator is tricked into requesting a specific package update from the configured package server. This can lead to the installation of unwanted addon code or site disruption. The attack is triggered via the rex-api-call parameter set to install package update, utilizing the addonkey and file variables to specify the package and version.Recommendations
Update to version 5.21.2.
Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redaxo