Record summary

CVE-2018-25353 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.

Description

Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated users to bypass file extension blacklist restrictions. Attackers with editor accounts can upload executable files by using obfuscated extensions like php71 or php53 to evade the blacklist filter and execute arbitrary code.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 26, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListThrough 5.5.1affected

Proofs of concept

1

Catalogued exploits

ExploitDBRedaxo CMS Mediapool Addon < 5.5.1 - Arbitrary File UploadExploitDB exploitby h0n1gsp3chtNot analyzed1 file
ExploitDB

PoC details

References

5