cve/2025/CVE-2025-27411.md

18 lines
736 B
Markdown
Raw Normal View History

2025-09-29 21:09:30 +02:00
### [CVE-2025-27411](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-27411)
![](https://img.shields.io/static/v1?label=Product&message=redaxo&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3C%205.18.3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-434%3A%20Unrestricted%20Upload%20of%20File%20with%20Dangerous%20Type&color=brightgreen)
### Description
REDAXO is a PHP-based CMS. In Redaxo before 5.18.3, the mediapool/media page is vulnerable to arbitrary file upload. This vulnerability is fixed in 5.18.3.
### POC
#### Reference
- https://github.com/redaxo/redaxo/security/advisories/GHSA-wppf-gqj5-fc4f
#### Github
No PoCs found on GitHub currently.