Missing Authorization in REDAXO - #VU153344
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to missing authorization in the backup add-on database export feature when selecting database tables for export. A remote user can export authentication tables containing active session identifiers or stay-logged-in keys to take over administrator accounts.
Exploitation requires that an administrator has granted the non-administrative user the backup[export] permission.