Redaxo CMS
cpe:2.3:a:redaxo:redaxo_cms:*:*:*:*:*:*:*
- 5.17.1
A vulnerability allowing arbitrary file upload has been identified in the MediaPool module of Redaxo CMS version 5.17.1. This vulnerability enables attackers to execute arbitrary code by uploading a crafted file. The issue arises from the application's insufficient validation of uploaded files, particularly in the PHP Template creation process. Additionally, the CronJob addon is also vulnerable, as it allows the execution of arbitrary PHP code on the application server.
Exploitation of this vulnerability could lead to authenticated arbitrary code execution on the server where Redaxo CMS is installed.
To reproduce this vulnerability, an authenticated admin user can upload a file containing malicious PHP code through the MediaPool module. Once the file is uploaded, the admin can create a new PHP template that includes the malicious code, which will then be executed on the server. Alternatively, the vulnerability can be reproduced by creating a cron job that executes arbitrary PHP code, leveraging the same file upload mechanism.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.