Cross-site request forgery in REDAXO - #VU140671

 

Cross-site request forgery in REDAXO - #VU140671

Published: August 1, 2026


Vulnerability identifier: #VU140671
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-352
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to cross-site request forgery in the backend user administration page=users/users when handling crafted GET requests that trigger the update path without a valid CSRF token. A remote attacker can trick a logged-in backend user with the users[] permission into opening an attacker-controlled page to escalate privileges.

User interaction is required, and the issue can also deactivate accounts or lock out the only administrator by modifying account status through the same update path.


Affected software

REDAXO

Remediation

Install security update from vendor's website.

REDAXO - update to 5.21.3

External References

Related Security Bulletins