Cross-site scripting in REDAXO - #VU140850

 

Cross-site scripting in REDAXO - #VU140850

Published: August 4, 2026


Vulnerability identifier: #VU140850
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in a victim's browser and perform actions in the victim's backend session.

The vulnerability exists due to improper neutralization of input during web page generation in the media, medialist, link, and linklist input widgets when rendering stored values into form field attributes. A remote user can store a specially crafted value to execute arbitrary script in a victim's browser and perform actions in the victim's backend session.

User interaction is required because a victim must open a form containing the affected widget.


Affected software

REDAXO

Remediation

Install security update from vendor's website.

REDAXO - update to 5.21.4

External References

Related Security Bulletins