top of page
perceptive_background_267k.jpg

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php le…

Published:

31 July 2026 at 00:00:00

Alert date:

31 July 2026 at 23:02:18

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

A file upload vulnerability exists in REDAXO CMS versions 5.18.2 through 5.21.0 in the rex_mediapool::isAllowedExtension function. Authenticated backend users with media upload permissions can bypass extension validation by uploading a JPEG/PHP polyglot file named with a pattern like shell.php.any.jpg. On web servers configured with multi-extension PHP handlers, such files can be executed as PHP scripts with web-server user privileges. This effectively allows remote code execution by a low-privileged authenticated attacker. The vulnerability resides in redaxo/src/addons/mediapool/lib/mediapool.php. The issue has been patched in REDAXO version 5.21.1. Users are advised to upgrade immediately to mitigate the risk of server compromise.

Technical details

Mitigation steps:

Affected products:

REDAXO CMS 5.18.2 - 5.21.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page