nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-25353 CVE-2018-25353
HIGH
Redaxo CMS Mediapool Addon 5.5.1 Arbitrary File Upload
Record summary
CVE-2018-25353 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated users to bypass file extension blacklist restrictions. Attackers with editor accounts can upload executable files by using obfuscated extensions like php71 or php53 to evade the blacklist filter and execute arbitrary code.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated May 26, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Redaxo CMS MediapoolBrowse Redaxo / Redaxo CMS Mediapool | CVE List | Through 5.5.1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBRedaxo CMS Mediapool Addon < 5.5.1 - Arbitrary File UploadExploitDB exploitby h0n1gsp3chtNot analyzed1 file
References
5Official Product Homepageproduct
https://redaxo.org/ Product Referenceproduct
https://redaxo.org/download/redaxo/5.5.1.zip ExploitDB-44891exploit
https://www.exploit-db.com/exploits/44891 VulnCheck Advisory: Redaxo CMS Mediapool Addon 5.5.1 Arbitrary File UploadThird-party advisory
https://www.vulncheck.com/advisories/redaxo-cms-mediapool-addon-arbitrary-file-upload