Cross-site scripting in REDAXO - #VU140850
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in a victim's browser and perform actions in the victim's backend session.
The vulnerability exists due to improper neutralization of input during web page generation in the media, medialist, link, and linklist input widgets when rendering stored values into form field attributes. A remote user can store a specially crafted value to execute arbitrary script in a victim's browser and perform actions in the victim's backend session.
User interaction is required because a victim must open a form containing the affected widget.