Cross-Site Scripting in REDAXO Media Manager
CVE-2026-63001
4.8MEDIUM
What is CVE-2026-63001?
The REDAXO content management system contains a cross-site scripting vulnerability in its Media Manager component. Specifically, versions prior to 5.21.2 contain a flaw in the mediaIsInUse() handler, which fails to properly escape media type names inserted into administrative backend HTML. This oversight allows an administrator with Media Manager privileges to store malicious HTML within a type name. As a result, when another administrator attempts to delete media linked to this type, the injected HTML is executed in their browser context. This can lead to session hijacking or unauthorized actions within the backend environment. Users are encouraged to upgrade to version 5.21.2 or later to mitigate these risks.
Affected Version(s)
core < 5.21.2
