Missing Authorization in REDAXO - #VU153341
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to delete application data and cause a denial of service.
The vulnerability exists due to missing authorization in the rex_api_package API function when handling package-management API requests with a valid CSRF token. A remote user can manage locally available packages to delete application data and cause a denial of service.
Exploitation requires a valid CSRF token for this API function; such tokens are normally generated only on administrator-restricted pages. Installations operating in live mode are not affected.