PT-2025-2731 · Unknown · Redaxo Cms

H4Ckr4V3N

·

Published

2025-01-06

·

Updated

2025-06-13

·

CVE-2024-46209

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions REDAXO CMS version 5.17.1
Description A stored cross-site scripting (XSS) vulnerability in the component /media/test.html of REDAXO CMS allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the password parameter.
Recommendations As a temporary workaround, consider disabling access to the /media/test.html component until a patch is available. Restrict the ability to inject crafted payloads into the password parameter to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-46209
GHSA-2P95-8XVM-2PJX

Affected Products

Redaxo Cms