2 results (0.004 seconds)

CVSS: 5.1EPSS: 0%CPEs: 1EXPL: 1

09 Jan 2025 — A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function of the file /index.php?page=structure&category_id=1&article_id=1&clang=1&function=edit_art&artstart=0 of the component Structure Management Page. The manipulation of the argument Article Name leads to cross site scripting. • https://geochen.medium.com/redaxo-cms-5-18-1-cross-site-scripting-7c9a872c72f6 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

25 Aug 2018 — An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.php?page=user. Se ha descubierto un problema en REDAXO CMS 4.7.2. Hay una vulnerabilidad de Cross-Site Request Forgery (CSRF) que puede añadir una cuenta de administrador mediante index.php? • https://github.com/redaxo/redaxo4/issues/420 • CWE-352: Cross-Site Request Forgery (CSRF) •