Skip to main content
Vulnerability Database/CVE-2026-63001

CVE-2026-63001: REDAXO CMS XSS Vulnerability

CVE-2026-63001 is a stored cross-site scripting vulnerability in REDAXO CMS that lets administrators inject malicious code through Media Manager type names. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-63001 Overview

CVE-2026-63001 is a stored cross-site scripting (XSS) vulnerability [CWE-79] in REDAXO, a PHP-based content management system. The flaw resides in the mediaIsInUse() handler within redaxo/src/addons/media_manager/lib/media_manager.php. The handler inserts a Media Manager type name into raw backend warning HTML without escaping it when invoked through MEDIA_IS_IN_USE. An administrator with Media Manager access can store HTML inside a type name. The payload executes in another administrator's browser when that user attempts to delete media referenced by the type's effects. Successful exploitation enables session theft or unauthorized backend actions. The issue is fixed in REDAXO version 5.21.2.

Critical Impact

A privileged Media Manager user can plant persistent JavaScript that executes in a higher-privileged administrator's session, enabling account takeover of the REDAXO backend.

Affected Products

  • REDAXO CMS versions prior to 5.21.2
  • REDAXO media_manager addon (media_manager.php)
  • REDAXO backend administrative interface

Discovery Timeline

  • 2026-09-23 - CVE-2026-63001 published to the National Vulnerability Database (NVD)
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-63001

Vulnerability Analysis

The vulnerability is a stored XSS flaw in the REDAXO backend. When a media file is scheduled for deletion, REDAXO checks whether the file is referenced by any Media Manager type effect. The mediaIsInUse() handler builds a warning message that includes the effect's name field and returns it as raw HTML. Because the name value is not escaped before rendering, any HTML or JavaScript stored in that field is executed by the browser of the reviewing administrator.

Exploitation requires two conditions. First, an attacker must already hold backend access with permission to create or edit Media Manager types. Second, a second administrator must trigger the deletion flow for a media asset referenced by the malicious type. When both conditions are met, the payload executes in the victim's authenticated backend session, enabling cookie theft, CSRF-style backend requests, or manipulation of REDAXO configuration.

Root Cause

The root cause is missing output encoding on user-controlled data. The pre-patch code concatenated (string) $sql->getValue('name') directly into an HTML anchor element rendered as a backend warning. REDAXO's standard escaper, rex_escape(), was not applied, allowing HTML metacharacters in the type name to break out of their textual context and execute as script.

Attack Vector

The attack is network-based but requires an authenticated attacker with high privileges and victim interaction. The attacker stores a payload in a Media Manager type name field. The payload lies dormant until another administrator initiates deletion of a media file consumed by that type's effects. The scope is changed because the injected script runs in the victim administrator's browser context, allowing actions on their behalf.

php
// Vulnerable code (pre-5.21.2) in redaxo/src/addons/media_manager/lib/media_manager.php
$message = '<a href="javascript:openPage(\'' . rex_url::backendPage('media_manager/types', ['effects' => 1, 'type_id' => $sql->getValue('type_id'), 'effect_id' => $sql->getValue('effect_id'), 'func' => 'edit']) . '\')">' . rex_i18n::msg('media_manager') . ' ' . rex_i18n::msg('media_manager_effect_name') . ': ' . (string) $sql->getValue('name') . '</a>';

// Patched code (5.21.2) - name value is escaped with rex_escape()
$message = '<a href="javascript:openPage(\'' . rex_url::backendPage('media_manager/types', ['effects' => 1, 'type_id' => $sql->getValue('type_id'), 'effect_id' => $sql->getValue('effect_id'), 'func' => 'edit']) . '\')">' . rex_i18n::msg('media_manager') . ' ' . rex_i18n::msg('media_manager_effect_name') . ': ' . rex_escape((string) $sql->getValue('name')) . '</a>';

Source: GitHub Commit 2daaa3a

Detection Methods for CVE-2026-63001

Indicators of Compromise

  • Media Manager type records whose name column contains HTML tags such as <script>, <img>, onerror=, or javascript: URIs.
  • Unexpected backend administrator sessions, new privileged accounts, or configuration changes following media deletion activity.
  • Outbound HTTP requests originating from administrator browsers to attacker-controlled hosts shortly after media management activity.

Detection Strategies

  • Query the REDAXO database for Media Manager type names containing angle brackets, quotes, or event handler substrings.
  • Review backend audit logs for creation or edit of Media Manager types by non-standard administrator accounts.
  • Inspect web server access logs for POST requests to index.php?page=media_manager/types with anomalous payload lengths or encoded HTML in form fields.

Monitoring Recommendations

  • Alert on script-like content stored in any REDAXO administrative metadata fields, including Media Manager types and effects.
  • Monitor administrator session activity for actions occurring immediately after a media deletion event, which may indicate script-driven abuse.
  • Track REDAXO version strings across hosted instances to identify systems still running versions prior to 5.21.2.

How to Mitigate CVE-2026-63001

Immediate Actions Required

  • Upgrade all REDAXO installations to version 5.21.2 or later without delay.
  • Audit existing Media Manager type names for stored HTML or JavaScript payloads and sanitize any suspicious entries.
  • Review the list of backend accounts with Media Manager access and revoke privileges that are not required.

Patch Information

The fix is delivered in REDAXO 5.21.2. The patch applies rex_escape() to the name value before concatenating it into the warning HTML rendered by mediaIsInUse(). Additional escaping was applied to related backend rendering paths as part of the same commit. See the GitHub Security Advisory GHSA-mf2p-wjp4-99pq, the REDAXO 5.21.2 Release, and the Pull Request Discussion for details.

Workarounds

  • Restrict Media Manager type creation and editing to a minimal set of trusted administrators until the patch is applied.
  • Instruct administrators to avoid deleting media assets from the backend until upgrading to 5.21.2.
  • Deploy a web application firewall rule that blocks HTML tags and JavaScript URI schemes in Media Manager type name submissions.
bash
# Verify installed REDAXO version and upgrade via Composer
php -r "echo file_get_contents('redaxo/src/core/const.php');" | grep REX_VERSION
composer require redaxo/core:^5.21.2
# After upgrade, clear the REDAXO cache from the backend or via CLI
php redaxo/bin/console cache:clear

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.