Stored XSS in REDAXO
Package
Affected versions
>= 5.12.0-beta1, <= 5.18.1
Patched versions
5.18.2
Description
Published to the GitHub Advisory Database
Feb 10, 2025
Reviewed
Feb 10, 2025
Last updated
Feb 10, 2025
Summary
Stored XSS in REDAXO 5.18.1 - Article / "content/edit".
Details
On the latest version of Redaxo, v5.18.1, the article name field is susceptible to stored XSS.
Impact
A malicious actor can easily steal cookie using this stored XSS and perform a session hijacking attack.
References