PT-2026-2105 · Redaxo · Backup Addon+1
Lukasz-Rybak
·
Published
2026-01-05
·
Updated
2026-01-20
·
CVE-2026-21857
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
REDAXO versions prior to 5.20.2
Description
REDAXO is a PHP-based content management system. Authenticated users with backup permissions can read arbitrary files within the webroot due to a path traversal issue in the Backup addon’s file export functionality. The Backup addon does not validate the
EXPDIR POST parameter against a permitted directory allowlist. An attacker can use relative paths containing ../ sequences, or even absolute paths within the document root, to include any readable file in a generated .tar.gz archive. The EXPDIR parameter is vulnerable to path traversal.Recommendations
Versions prior to 5.20.2 should be updated to version 5.20.2 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Backup Addon
Redaxo