PT-2026-2105 · Redaxo · Backup Addon+1
Lukasz-Rybak
·
Publicado
2026-01-05
·
Atualizado
2026-01-20
·
CVE-2026-21857
CVSS v4.0
8.3
Alta
| Vetor | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
REDAXO versions prior to 5.20.2
Description
REDAXO is a PHP-based content management system. Authenticated users with backup permissions can read arbitrary files within the webroot due to a path traversal issue in the Backup addon’s file export functionality. The Backup addon does not validate the
EXPDIR POST parameter against a permitted directory allowlist. An attacker can use relative paths containing ../ sequences, or even absolute paths within the document root, to include any readable file in a generated .tar.gz archive. The EXPDIR parameter is vulnerable to path traversal.Recommendations
Versions prior to 5.20.2 should be updated to version 5.20.2 or later.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Backup Addon
Redaxo