Cross-site scripting in REDAXO - #VU140852
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in rex_media_service when handling uploaded SVG files before sanitization completes. A remote user can upload a specially crafted SVG file and cause script execution in the origin serving the public media path.
User interaction is required to open the raw file URL as a top-level navigation or load it in an iframe, and exploitation requires mediapool upload or edit permissions.