PT-2026-97328 · Redaxo · Redaxo

CVE-2026-63000

·

Published

2026-09-23

·

Updated

2026-09-29

CVSS v3.1

6.4

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions REDAXO versions prior to 5.21.2
Description REDAXO is a PHP-based content management system. The rex api install package update() function within the install addon fails to override the requiresCsrfProtection() method, which defaults to false in the base class. This allows an unauthenticated attacker to perform a Cross-Site Request Forgery (CSRF) attack, where a logged-in administrator is tricked into requesting a specific package update from the configured package server. This can lead to the installation of unwanted addon code or site disruption. The attack is triggered via the rex-api-call parameter set to install package update, utilizing the addonkey and file variables to specify the package and version.
Recommendations Update to version 5.21.2.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63000
GHSA-M8R3-22V6-G877

Affected Products

Redaxo