CVE-2018-25353 HIGH

CVE-2018-25353: Redaxo CMS Mediapool Addon 5.5.1 Arbitrary File Upload

Vendor Redaxo
Product Redaxo CMS Mediapool
Weakness CWE-863 · Incorrect authorization
Published May 23, 2026
Last update May 26, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated users to bypass file extension blacklist restrictions. Attackers with editor accounts can upload executable files by using obfuscated extensions like php71 or php53 to evade the blacklist filter and execute arbitrary code.

Key dates

02Disclosure timeline

May 23, 2026 CVE published
May 26, 2026 Record updated