Medium severity4.8NVD Advisory· Published Sep 23, 2026
CVE-2026-63002
CVE-2026-63002
Description
REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts filenames held in $diffFiles from the media filesystem into the Mediapool Sync page without rex_escape(). An attacker who can place an unregistered file with HTML metacharacters in the media directory can execute script in the browser of a backend user with media[sync] permission when that user opens the Sync page, enabling session theft or unauthorized backend actions. This issue is fixed in version 5.21.2.
Affected products
2Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.