Redaxo CMS Mediapool Addon 5.5.1 and older contains an...
High severity
Unreviewed
Published
May 26, 2026
to the GitHub Advisory Database
•
Updated May 26, 2026
Description
Published by the National Vulnerability Database
May 23, 2026
Published to the GitHub Advisory Database
May 26, 2026
Last updated
May 26, 2026
Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated users to bypass file extension blacklist restrictions. Attackers with editor accounts can upload executable files by using obfuscated extensions like php71 or php53 to evade the blacklist filter and execute arbitrary code.
References