Medium severity5.4NVD Advisory· Published Jan 6, 2025· Updated Jun 17, 2026
CVE-2024-46209
CVE-2024-46209
Description
A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS v5.17.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the password parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
redaxo/sourcePackagist | <= 5.17.1 | — |
Affected products
3- REDAXO CMS/REDAXO CMSdescription
Patches
Vulnerability mechanics
References
3- github.com/h4ckr4v3n/CVE-2024-46209/blob/main/REDAXO%20Stored%20XSS%20%2B%20RCE.pdfnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-2p95-8xvm-2pjxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-46209ghsaADVISORY
News mentions
0No linked articles in our index yet.