Cross-site request forgery in REDAXO - #VU140669
Published: August 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to roll back article content without authorization.
The vulnerability exists due to cross-site request forgery in the article history plugin bootstrap when handling a crafted top-level GET request with the rex_history_function=snap parameter. A remote attacker can trick a logged-in victim into opening an attacker-controlled page to roll back article content without authorization.
The issue restores a previously stored snapshot over the current article content, and user interaction is required from a victim holding the history[article_rollback] permission.