Cross-site request forgery in REDAXO - #VU140671
Published: August 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to cross-site request forgery in the backend user administration page=users/users when handling crafted GET requests that trigger the update path without a valid CSRF token. A remote attacker can trick a logged-in backend user with the users[] permission into opening an attacker-controlled page to escalate privileges.
User interaction is required, and the issue can also deactivate accounts or lock out the only administrator by modifying account status through the same update path.