Cross-site scripting in REDAXO - #VU140670
Published: August 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the victim's browser within the backend origin.
The vulnerability exists due to cross-site scripting in the backend media pool detail page when handling the opener_link request parameter. A remote attacker can send a specially crafted link to inject arbitrary HTML and JavaScript and execute arbitrary JavaScript in the victim's browser within the backend origin.
User interaction is required, and exploitation succeeds only when a logged-in backend user with media permissions opens a crafted link, opener_input_field is absent from the request, and file_id references an existing media file.