SB2026080417 - Multiple vulnerabilities in REDAXO
Published: August 4, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 6 vulnerabilities.
1) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the frontend preview mode of the structure/version and structure/history plugins when handling preview requests for article content selected by request parameters. A remote user can send a crafted frontend request to disclose sensitive information.
Exploitation requires an active backend session and the relevant plugin to be installed and enabled. The issue can expose unpublished working versions, historic snapshots, and previously deleted content when such data exists for the targeted article.
2) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify arbitrary media files by moving them into a permitted category.
The vulnerability exists due to missing authorization in the media pool bulk move operation when processing selected files for category reassignment. A remote user can select files from categories they are not permitted to control and move them into a category they control to modify arbitrary media files by replacing their contents.
The issue affects authenticated backend sessions and does not require a crafted request or victim interaction.
3) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify other editors' content outside their authorized categories.
The vulnerability exists due to authorization bypass through a user-controlled key in slice operations and related service-layer handlers when processing requests that supply an article reference for permission checks and an independent slice reference for the mutation. A remote user can send a specially crafted request to modify other editors' content outside their authorized categories.
The issue affects deleting slices, changing slice status, moving slices, and, with a matching module/template constellation, overwriting content. The attack is performed entirely within the user's authenticated session and does not require user interaction.
4) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in a victim's browser and perform actions in the victim's backend session.
The vulnerability exists due to improper neutralization of input during web page generation in the media, medialist, link, and linklist input widgets when rendering stored values into form field attributes. A remote user can store a specially crafted value to execute arbitrary script in a victim's browser and perform actions in the victim's backend session.
User interaction is required because a victim must open a form containing the affected widget.
5) Improper Authentication (CVE-ID: N/A)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication and obtain a backend session for an existing account.
The vulnerability exists due to improper authentication in the temporary login token handling of the structure/history plugin when processing a temporary frontend login request. A remote attacker can bring the secret into a predictable state and forge a temporary login token to bypass authentication and obtain a backend session for an existing account.
Only installations with the structure/history plugin installed and activated are vulnerable, and the issue can affect administrator accounts.
6) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in rex_media_service when handling uploaded SVG files before sanitization completes. A remote user can upload a specially crafted SVG file and cause script execution in the origin serving the public media path.
User interaction is required to open the raw file URL as a top-level navigation or load it in an iframe, and exploitation requires mediapool upload or edit permissions.
Remediation
Install update from vendor's website.
References
- https://github.com/redaxo/core/security/advisories/GHSA-v4m9-jvvr-83cx
- https://github.com/redaxo/core/security/advisories/GHSA-j9mx-x52f-48cw
- https://github.com/redaxo/core/security/advisories/GHSA-5m63-c3qx-wq8v
- https://github.com/redaxo/core/security/advisories/GHSA-5wmj-5x79-rr87
- https://github.com/redaxo/core/security/advisories/GHSA-px8f-whj8-hrpq
- https://github.com/redaxo/core/security/advisories/GHSA-2p3g-jr7p-qwwx