Skip to main content
Vulnerability Database/CVE-2026-63002

CVE-2026-63002: REDAXO CMS XSS Vulnerability

CVE-2026-63002 is a cross-site scripting flaw in REDAXO CMS that allows attackers to execute malicious scripts in backend users' browsers. This article covers the technical details, affected versions, and mitigation strategies.

Updated:

CVE-2026-63002 Overview

REDAXO is a PHP-based content management system used to build and manage websites. CVE-2026-63002 is a stored cross-site scripting (XSS) vulnerability [CWE-79] in the Mediapool Sync page. The file redaxo/src/addons/mediapool/pages/sync.php inserts filenames held in $diffFiles from the media filesystem into the page without calling rex_escape(). An attacker who can place an unregistered file with HTML metacharacters in the media directory can execute script in the browser of a backend user with the media[sync] permission. The issue is fixed in REDAXO version 5.21.2.

Critical Impact

Successful exploitation enables session theft or unauthorized backend actions performed in the context of an authenticated REDAXO administrator viewing the Sync page.

Affected Products

  • REDAXO core versions prior to 5.21.2
  • REDAXO Mediapool addon (redaxo/src/addons/mediapool/pages/sync.php)
  • REDAXO backend installations exposing the media[sync] permission to operators

Discovery Timeline

  • 2026-09-23 - CVE-2026-63002 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-63002

Vulnerability Analysis

The vulnerability is a stored XSS in the Mediapool Sync workflow. When a backend user opens the Sync page, REDAXO builds a diff of files present on the filesystem but not registered in the media database. The $diffFiles array contains raw filenames read from disk. sync.php writes those filenames directly into the rendered HTML output without passing them through rex_escape(). Any HTML metacharacter contained in a filename is therefore interpreted as markup by the browser. Because the payload is served from the trusted backend origin and executes in an authenticated session, attackers can read session tokens, issue authenticated requests, or manipulate content through the CMS backend.

Root Cause

The root cause is missing output encoding of untrusted data during HTML rendering. REDAXO provides rex_escape() for context-appropriate escaping, but sync.php omitted it when concatenating filenames from $diffFiles into the response body. Filesystem entries are treated as trusted strings even though the media directory can receive files from lower-privileged workflows or external processes.

Attack Vector

Exploitation requires write access to the media directory so the attacker can create a file whose name contains an HTML or JavaScript payload, for example "><script>...</script>.jpg. The file must remain unregistered in the Mediapool so it appears in $diffFiles. A backend user holding the media[sync] permission triggers execution simply by opening the Sync page. User interaction is required, but no exploit is needed against the victim beyond page navigation.

The following patch excerpt from the referenced commit shows the escaping pattern REDAXO applies elsewhere in the codebase to remediate similar issues:

php
// Before
$message = '<a href="javascript:openPage(\'' . rex_url::backendPage('media_manager/types', ['effects' => 1, 'type_id' => $sql->getValue('type_id'), 'effect_id' => $sql->getValue('effect_id'), 'func' => 'edit']) . '\')">' . rex_i18n::msg('media_manager') . ' ' . rex_i18n::msg('media_manager_effect_name') . ': ' . (string) $sql->getValue('name') . '</a>';

// After
$message = '<a href="javascript:openPage(\'' . rex_url::backendPage('media_manager/types', ['effects' => 1, 'type_id' => $sql->getValue('type_id'), 'effect_id' => $sql->getValue('effect_id'), 'func' => 'edit']) . '\')">' . rex_i18n::msg('media_manager') . ' ' . rex_i18n::msg('media_manager_effect_name') . ': ' . rex_escape((string) $sql->getValue('name')) . '</a>';

Source: GitHub Commit 2daaa3a

Detection Methods for CVE-2026-63002

Indicators of Compromise

  • Files present in the REDAXO media directory whose names contain HTML metacharacters such as <, >, ", or '.
  • Unregistered media entries that appear in Mediapool Sync diffs but were not uploaded through the REDAXO backend.
  • Backend audit records showing unexpected session activity or content changes shortly after a media[sync] user opened the Sync page.

Detection Strategies

  • Review web server access logs for anomalous requests to index.php?page=mediapool/sync followed by unusual backend API calls from the same session.
  • Scan the media filesystem for filenames matching regular expressions containing <, >, script, or on[a-z]+= patterns.
  • Compare files on disk against the rex_media database table to enumerate unregistered entries that could feed $diffFiles.

Monitoring Recommendations

  • Alert on newly created files in the media directory whose names include HTML or JavaScript syntax.
  • Monitor backend user sessions for token reuse from unexpected client fingerprints after Sync page access.
  • Track REDAXO version inventory to identify hosts still running versions prior to 5.21.2.

How to Mitigate CVE-2026-63002

Immediate Actions Required

  • Upgrade REDAXO core to version 5.21.2 or later across all environments.
  • Audit the media directory and remove any files whose names contain HTML metacharacters.
  • Restrict the media[sync] permission to a minimal set of trusted administrators until the patch is applied.

Patch Information

The vulnerability is fixed in REDAXO 5.21.2. The fix adds rex_escape() around user-controlled values rendered as raw backend HTML on the Mediapool Sync page. Full details are available in the GitHub Security Advisory GHSA-w998-qmw9-mf4m, the GitHub Pull Request #6581, and the REDAXO 5.21.2 Release.

Workarounds

  • Prevent write access to the media directory by processes or users other than the REDAXO backend.
  • Temporarily revoke the media[sync] permission from all backend accounts until the upgrade completes.
  • Enforce a Content Security Policy on the backend that blocks inline script execution to limit the impact of stored XSS payloads.
bash
# Upgrade REDAXO core to the patched release
cd /path/to/redaxo
composer require redaxo/core:^5.21.2

# Identify unregistered files with suspicious characters in the media directory
find ./redaxo/data/media -type f \( -name '*<*' -o -name '*>*' -o -name '*"*' -o -name "*'*" \)

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.