Stored XSS in REDAXO 5.18.1 - Article / "content/edit".
On the latest version of Redaxo, v5.18.1, the article name field is susceptible to stored XSS.
A malicious actor can easily steal cookie using this stored XSS and perform a session hijacking attack.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2025-02-10T18:55:06Z",
"nvd_published_at": null,
"severity": "MODERATE"
}