Stored Cross-Site Scripting Vulnerability in REDAXO CMS v5.17.1
CVE-2024-46209

Currently unrated

Key Information:

Vendor

REDAXO

Vendor
CVE Published:
6 January 2025

What is CVE-2024-46209?

A stored cross-site scripting vulnerability exists in the REDAXO CMS version 5.17.1 that enables attackers to inject malicious scripts through the crafted payload in the password parameter. This vulnerability can lead to unauthorized script execution in the context of the affected user, compromising session tokens and enabling the attacker to manipulate web content. Proper validation and sanitization of user inputs are crucial to mitigate this risk.

References

Timeline

  • Vulnerability published

.