


Perceptive Security
SOC/SIEM Consultancy

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php le…
Published:
30 juli 2026 om 22:00:00
Alert date:
31 juli 2026 om 21:02:18
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A file upload vulnerability exists in REDAXO CMS versions 5.18.2 through 5.21.0 in the rex_mediapool::isAllowedExtension function. Authenticated backend users with media upload permissions can bypass extension validation by uploading a JPEG/PHP polyglot file named with a pattern like shell.php.any.jpg. On web servers configured with multi-extension PHP handlers, such files can be executed as PHP scripts with web-server user privileges. This effectively allows remote code execution by a low-privileged authenticated attacker. The vulnerability resides in redaxo/src/addons/mediapool/lib/mediapool.php. The issue has been patched in REDAXO version 5.21.1. Users are advised to upgrade immediately to mitigate the risk of server compromise.
Technical details
Mitigation steps:
Affected products:
REDAXO CMS 5.18.2 - 5.21.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-53599
https://github.com/redaxo/core/commit/462e36896bb65d292ba22d711044c23c9cfb0340
https://github.com/redaxo/core/pull/6538
https://github.com/redaxo/core/releases/tag/5.21.1
https://github.com/redaxo/core/security/advisories/GHSA-98pp-vccm-qm25
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
