Cross-site scripting in REDAXO - #VU135825
Published: June 29, 2026
REDAXO
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the mediaIsInUse() function in the media manager addon when rendering a warning message for deletion of a media file referenced by a Media Manager effect. A remote privileged user can store a crafted type name to execute arbitrary script in a victim's browser.
User interaction is required, as the victim must attempt to delete a media file linked to the affected type's effects.