PT-2026-97330 · Redaxo · Redaxo
CVE-2026-63002
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
REDAXO versions prior to 5.21.2
Description
REDAXO is a PHP-based content management system. The Mediapool Sync page, located at the endpoint
redaxo/src/addons/mediapool/pages/sync.php, fails to apply the rex escape() function (which performs HTML escaping) to filenames stored in the $diffFiles variable when rendering them into HTML. An attacker who can place a file with HTML metacharacters in the /media directory can execute arbitrary JavaScript in the browser of any backend user with media[sync] permissions. This stored cross-site scripting (XSS) can lead to session theft, credential theft, and unauthorized backend actions.Recommendations
Update REDAXO to version 5.21.2.
As a temporary workaround, restrict access to the
redaxo/src/addons/mediapool/pages/sync.php page or limit the media[sync] permission to trusted users only.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Redaxo