Cross-site request forgery in REDAXO - #VU135823
Published: June 29, 2026
REDAXO
Detailed vulnerability description
The vulnerability allows a remote attacker to trigger unauthorized package updates.
The vulnerability exists due to cross-site request forgery in rex_api_install_package_update when handling package update requests. A remote attacker can trick an authenticated administrator into visiting a crafted page to trigger unauthorized package updates.
User interaction is required, and exploitation succeeds when an authenticated administrator visits a malicious page with an active session.