PT-2026-97330 · Redaxo · Redaxo

CVE-2026-63002

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions REDAXO versions prior to 5.21.2
Description REDAXO is a PHP-based content management system. The Mediapool Sync page, located at the endpoint redaxo/src/addons/mediapool/pages/sync.php, fails to apply the rex escape() function (which performs HTML escaping) to filenames stored in the $diffFiles variable when rendering them into HTML. An attacker who can place a file with HTML metacharacters in the /media directory can execute arbitrary JavaScript in the browser of any backend user with media[sync] permissions. This stored cross-site scripting (XSS) can lead to session theft, credential theft, and unauthorized backend actions.
Recommendations Update REDAXO to version 5.21.2. As a temporary workaround, restrict access to the redaxo/src/addons/mediapool/pages/sync.php page or limit the media[sync] permission to trusted users only.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63002
GHSA-W998-QMW9-MF4M

Affected Products

Redaxo