Cross-site request forgery in REDAXO - #VU140668
Published: August 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause loss of recovery data.
The vulnerability exists due to cross-site request forgery in the article history plugin history administration page when handling a crafted top-level GET request with the func=clearall parameter. A remote attacker can trick a logged-in victim into opening an attacker-controlled page to cause loss of recovery data.
This action permanently deletes every stored article snapshot and requires user interaction from an administrator victim who is logged into the backend.