Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2024-13209
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function of the file /index.php?page=structure&category_id=1&article_id=1&clang=1&function=edit_art&artstart=0 of the component Structure Management Page. The manipulation of the argument Article Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-25298
Disclosure Date: February 17, 2024 (last updated February 26, 2025)
An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.
0
Attacker Value
Unknown
CVE-2024-25301
Disclosure Date: February 14, 2024 (last updated February 26, 2025)
Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.
0
Attacker Value
Unknown
CVE-2024-25300
Disclosure Date: February 14, 2024 (last updated February 26, 2025)
A cross-site scripting (XSS) vulnerability in Redaxo v5.15.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Template section.
0
Attacker Value
Unknown
CVE-2021-39458
Disclosure Date: September 09, 2021 (last updated February 23, 2025)
Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables.
0
Attacker Value
Unknown
CVE-2021-39459
Disclosure Date: September 09, 2021 (last updated February 23, 2025)
Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code.
0
Attacker Value
Unknown
CVE-2018-18198
Disclosure Date: October 09, 2018 (last updated November 27, 2024)
The $opener_input_field variable in addons/mediapool/pages/index.php in REDAXO 5.6.3 is not effectively filtered and is output directly to the page. The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=[XSS] request.
0
Attacker Value
Unknown
CVE-2018-18199
Disclosure Date: October 09, 2018 (last updated November 27, 2024)
Mediamanager in REDAXO before 5.6.4 has XSS.
0
Attacker Value
Unknown
CVE-2018-18200
Disclosure Date: October 09, 2018 (last updated November 27, 2024)
There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4.
0
Attacker Value
Unknown
CVE-2018-17830
Disclosure Date: October 01, 2018 (last updated November 27, 2024)
The $args variable in addons/mediapool/pages/index.php in REDAXO 5.6.2 is not effectively filtered, because names are not restricted (only values are restricted). The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=&args[ substring.
0