CVE-2026-53599

high

Description

REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polyglot named shell.php.any.jpg, which web servers with multi-extension PHP handlers can execute as the web-server user. This issue is fixed in version 5.21.1.

References

https://github.com/redaxo/core/security/advisories/GHSA-98pp-vccm-qm25

https://github.com/redaxo/core/releases/tag/5.21.1

https://github.com/redaxo/core/pull/6538

https://github.com/redaxo/core/commit/462e36896bb65d292ba22d711044c23c9cfb0340

Details

Source: Mitre, NVD

Published: 2026-07-31

Updated: 2026-07-31

Risk Information

CVSS v2

Base Score: 7.1

Vector: CVSS2#AV:N/AC:H/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High