
CVE-2024-13209 – Redaxo CMS Structure Management Page index.php cross site scripting
https://notcve.org/view.php?id=CVE-2024-13209
09 Jan 2025 — A vulnerability was found in Redaxo CMS 5.18.1. It has been classified as problematic. Affected is an unknown function of the file /index.php?page=structure&category_id=1&article_id=1&clang=1&function=edit_art&artstart=0 of the component Structure Management Page. The manipulation of the argument Article Name leads to cross site scripting. • https://geochen.medium.com/redaxo-cms-5-18-1-cross-site-scripting-7c9a872c72f6 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2018-15850
https://notcve.org/view.php?id=CVE-2018-15850
25 Aug 2018 — An issue was discovered in REDAXO CMS 4.7.2. There is a CSRF vulnerability that can add an administrator account via index.php?page=user. Se ha descubierto un problema en REDAXO CMS 4.7.2. Hay una vulnerabilidad de Cross-Site Request Forgery (CSRF) que puede añadir una cuenta de administrador mediante index.php? • https://github.com/redaxo/redaxo4/issues/420 • CWE-352: Cross-Site Request Forgery (CSRF) •