Stored XSS in REDAXO 5.18.1 - Article / "content/edit".
On the latest version of Redaxo, v5.18.1, the article name field is susceptible to stored XSS.
A malicious actor can easily steal cookie using this stored XSS and perform a session hijacking attack.
{ "severity": "MODERATE", "github_reviewed_at": "2025-02-10T18:55:06Z", "nvd_published_at": null, "cwe_ids": [ "CWE-79" ], "github_reviewed": true }