CVE-2018-18198: Redaxo
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
The $opener_input_field variable in addons/mediapool/pages/index.php in REDAXO 5.6.3 is not effectively filtered and is output directly to the page. The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=[XSS] request.
Affected products
- Redaxo Redaxo: version 5.6.3 only
Published 2018-10-09. Last modified 2026-06-17.