Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2024-13209

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function of the file /index.php?page=structure&category_id=1&article_id=1&clang=1&function=edit_art&artstart=0 of the component Structure Management Page. The manipulation of the argument Article Name leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2024-25298

Disclosure Date: February 17, 2024 (last updated February 26, 2025)
An issue was discovered in REDAXO version 5.15.1, allows attackers to execute arbitrary code and obtain sensitive information via modules.modules.php.
Attacker Value
Unknown

CVE-2024-25301

Disclosure Date: February 14, 2024 (last updated February 26, 2025)
Redaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.
Attacker Value
Unknown

CVE-2024-25300

Disclosure Date: February 14, 2024 (last updated February 26, 2025)
A cross-site scripting (XSS) vulnerability in Redaxo v5.15.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter in the Template section.
Attacker Value
Unknown

CVE-2021-39458

Disclosure Date: September 09, 2021 (last updated February 23, 2025)
Triggering an error page of the import process in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user has to alternate the files of a vaild file backup. This leads of leaking the database credentials in the environment variables.
Attacker Value
Unknown

CVE-2021-39459

Disclosure Date: September 09, 2021 (last updated February 23, 2025)
Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code.
Attacker Value
Unknown

CVE-2018-18198

Disclosure Date: October 09, 2018 (last updated November 27, 2024)
The $opener_input_field variable in addons/mediapool/pages/index.php in REDAXO 5.6.3 is not effectively filtered and is output directly to the page. The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=[XSS] request.
0
Attacker Value
Unknown

CVE-2018-18199

Disclosure Date: October 09, 2018 (last updated November 27, 2024)
Mediamanager in REDAXO before 5.6.4 has XSS.
0
Attacker Value
Unknown

CVE-2018-18200

Disclosure Date: October 09, 2018 (last updated November 27, 2024)
There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4.
0
Attacker Value
Unknown

CVE-2018-17830

Disclosure Date: October 01, 2018 (last updated November 27, 2024)
The $args variable in addons/mediapool/pages/index.php in REDAXO 5.6.2 is not effectively filtered, because names are not restricted (only values are restricted). The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=&args[ substring.
0