Vulnerability GHSA-w998-qmw9-mf4m

Medium Risk
MEDIUM RISK
CVSS Score: 4.8
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 days ago
September 23, 2026 at 02:06 PM UTC
REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1

Summary

REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames

Details

Summary

The mediapool sync page (sync.php) renders filenames from the /media filesystem directory directly into HTML without applying rex_escape() (i.e., htmlspecialchars). Any file placed in the media directory whose filename contains HTML metacharacters will execute JavaScript in the browser of any backend user who views the sync page.

Details

In redaxo/src/addons/mediapool/pages/sync.php, the variable $diffFiles is populated from actual filesystem filenames (files in /media/ not yet registered in the database). These filenames are then rendered without escaping:

File: redaxo/src/addons/mediapool/pages/sync.php:119-120

foreach ($diffFiles as $file) {
    if (is_writable(rex_path::media($file))) {
        $e = [];
        $e['label'] = '<label>' . $file . '</label>';          // NO rex_escape!
        $e['field'] = '<input type="checkbox" name="sync_files[]" value="' . $file . '" />'; // NO rex_escape!
        $writable[] = $e;
    } else {
        $notWritable[] = $file;
    }
}

File: redaxo/src/addons/mediapool/pages/sync.php:170

$fragment->setVar('body', '<ul><li>' . implode('</li><li>', $notWritable) . '</li></ul>', false);
// $notWritable contains unescaped filenames

By contrast, all other filename displays in the codebase use rex_escape($fname) (e.g., media.detail.php:236, media.list.php). The sync page is accessible to any backend user with the media[sync] permission (not exclusively admins).

PoC

  1. Place a file named <img src=x onerror=alert(document.cookie)>.txt into the REDAXO /media/ directory (via backup restore or server access) without adding it to the media database.
  2. Log in as any backend user with media[sync] permission.
  3. Navigate to Mediapool → Sync.
  4. The XSS payload executes immediately, stealing the admin session cookie.

Impact

Stored XSS in the admin panel. An attacker who can place files in the media directory (via admin-level backup restore or server access) can achieve persistent XSS against all users who visit the sync page, including higher-privileged admins. This enables session hijacking, credential theft, and full CMS takeover.

Fix

Apply rex_escape() to all filename variables before inserting into HTML:

$e['label'] = '<label>' . rex_escape($file) . '</label>';
$e['field'] = '<input type="checkbox" name="sync_files[]" value="' . rex_escape($file) . '" />';
// ...
$fragment->setVar('body', '<ul><li>' . implode('</li><li>', array_map('rex_escape', $notWritable)) . '</li></ul>', false);

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Medium Risk
3 days ago
REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-4f5f-j737-pm58
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-4f5f-j737-pm58
Medium Risk
4 days ago
REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-m8r3-22v6-g877
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-m8r3-22v6-g877
Medium Risk
4 days ago
REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()`
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-mf2p-wjp4-99pq
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-mf2p-wjp4-99pq
High Risk
1 month ago
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
5.18.2 - 5.20.2 and 5.21.0 GHSA-98pp-vccm-qm25
5.18.2 - 5.20.2 and 5.21.0 GHSA-98pp-vccm-qm25
Low Risk
5 months ago
REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 GHSA-xq4j-g85q-wf97
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 GHSA-xq4j-g85q-wf97
View all vulnerabilities for these packages

Impacted packages

Timeline

Published
4 days ago
September 23, 2026 at 02:06 PM UTC
Fixed (5.21.2)
3 months ago
June 29, 2026 at 09:41 AM UTC
Last Modified
4 days ago
September 23, 2026 at 02:15 PM UTC