Vulnerability GHSA-m8r3-22v6-g877

Medium Risk
MEDIUM RISK
CVSS Score: 6.4
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 days ago
September 23, 2026 at 02:09 PM UTC
REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1

Summary

REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates

Details

Summary

The rex_api_install_package_update API function (install addon) does not override requiresCsrfProtection(), which defaults to false in the base class rex_api_function. Any authenticated admin can therefore be tricked via a CSRF attack into silently triggering a package update from the REDAXO package server.

Details

File: redaxo/src/core/lib/api_function.php:277-280

protected function requiresCsrfProtection()
{
    return false;  // DEFAULT — subclasses must opt in
}

File: redaxo/src/addons/install/lib/api/api_package_update.php:8-39

class rex_api_install_package_update extends rex_api_function
{
    public function execute()
    {
        if (!rex::getUser()?->isAdmin()) {
            throw new rex_api_exception('You do not have the permission!');
        }
        $addonkey = rex_request('addonkey', 'string');
        $fileId = rex_request('file', 'int');
        $installer = new rex_install_package_update();
        // ... downloads and installs $addonkey version $fileId from redaxo.org
    }
    // requiresCsrfProtection() NOT overridden — defaults to false
}

For comparison, rex_api_install_package_add and rex_api_install_package_delete both correctly return true. Only rex_api_install_package_update is missing this.

PoC

<!-- Attacker-controlled page -->
<img src="https://victim-redaxo.example.com/index.php?page=install/packages&rex-api-call=install_package_update&addonkey=some_addon&file=42" />

When an authenticated admin visits this page, the request is automatically made with their session cookie, causing some_addon to be updated to version file_id=42.

Impact

An attacker who can lure an admin to a malicious page can force-install specific addon versions. If combined with a supply-chain compromise of a package on redaxo.org, or by targeting a downgrade to a known-vulnerable version, this becomes a remote code execution vector. Even without supply-chain compromise, it can be used to disrupt the site by forcing unwanted updates.

Fix

Add requiresCsrfProtection() to rex_api_install_package_update:

protected function requiresCsrfProtection()
{
    return true;
}

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Medium Risk
3 days ago
REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-4f5f-j737-pm58
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-4f5f-j737-pm58
Medium Risk
4 days ago
REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-w998-qmw9-mf4m
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-w998-qmw9-mf4m
Medium Risk
4 days ago
REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()`
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-mf2p-wjp4-99pq
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-mf2p-wjp4-99pq
High Risk
1 month ago
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
5.18.2 - 5.20.2 and 5.21.0 GHSA-98pp-vccm-qm25
5.18.2 - 5.20.2 and 5.21.0 GHSA-98pp-vccm-qm25
Low Risk
5 months ago
REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 GHSA-xq4j-g85q-wf97
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 GHSA-xq4j-g85q-wf97
View all vulnerabilities for these packages

Impacted packages

Timeline

Published
4 days ago
September 23, 2026 at 02:09 PM UTC
Fixed (5.21.2)
3 months ago
June 29, 2026 at 09:41 AM UTC
Last Modified
4 days ago
September 23, 2026 at 02:15 PM UTC