REDAXO CMS Remote Code Execution Vulnerability in Template Management Component

Vulnerability

A remote code execution vulnerability has been identified in REDAXO CMS version 5.20.0. This issue arises in the template management component, where remote authenticated administrators can execute arbitrary operating system commands. The vulnerability is exploited by injecting PHP code into an active template, with the payload being executed when visitors access frontend pages that use the compromised template.

Impact

Exploitation of this vulnerability allows for remote code execution on the server, with the injected PHP code executed in the context of the web server user. This could lead to a complete system compromise, including unauthorized access to sensitive files, establishment of a reverse shell for persistent access, and potential escalation of privileges to gain full control over the hosting environment.

Reproduction

To reproduce this vulnerability, log in as an administrator and navigate to the templates section. Select the default template and mark it as active. Inject a PHP payload into the template section, such as one that executes a command like 'cat /etc/passwd' or a reverse shell payload. After saving the template, visit the base URL to trigger the payload execution. Screenshots demonstrating this process are available in the CVE reference.

Remediation

Users are advised to update to REDAXO CMS version 5.20.1, which addresses this vulnerability.

Added: Nov 25, 2025, 4:17 PM
Updated: Nov 25, 2025, 10:53 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
7.5
exploitability
6.3
remediation
0.0
relevance
1.1
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.