PT-2026-2105 · Redaxo · Backup Addon+1

Lukasz-Rybak

·

Publicado

2026-01-05

·

Atualizado

2026-01-20

·

CVE-2026-21857

CVSS v4.0

8.3

Alta

VetorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions REDAXO versions prior to 5.20.2
Description REDAXO is a PHP-based content management system. Authenticated users with backup permissions can read arbitrary files within the webroot due to a path traversal issue in the Backup addon’s file export functionality. The Backup addon does not validate the EXPDIR POST parameter against a permitted directory allowlist. An attacker can use relative paths containing ../ sequences, or even absolute paths within the document root, to include any readable file in a generated .tar.gz archive. The EXPDIR parameter is vulnerable to path traversal.
Recommendations Versions prior to 5.20.2 should be updated to version 5.20.2 or later.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-21857
GHSA-824X-88XG-CWRV

Produtos afetados

Backup Addon
Redaxo