logo

Database

Server side cross-site scripting In redaxo/source

Description

Stored XSS in REDAXO

Summary

Stored XSS in REDAXO 5.18.1 - Article / "content/edit".

Details

On the latest version of Redaxo, v5.18.1, the article name field is susceptible to stored XSS.

Impact

A malicious actor can easily steal cookie using this stored XSS and perform a session hijacking attack.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions