CVE-2018-25353: Redaxo CMS Mediapool Addon 5.5.1 Arbitrary File Upload
Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated users to bypass file extension blacklist restrictions. Attackers with editor accounts can upload executable files by using obfuscated extensions like php71 or php53 to evade the blacklist filter and execute arbitrary code.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Redaxo CMS Mediapool Addonto a version that resolves this vulnerability.Fixed in 5.5.1
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25353?
The severity of CVE-2018-25353 is rated as high, with a score of 8.8.
How do I fix CVE-2018-25353?
To fix CVE-2018-25353, update the Redaxo CMS Mediapool Addon to a version that is not vulnerable.
Who is affected by CVE-2018-25353?
Authenticated users, specifically those with editor accounts on Redaxo CMS Mediapool Addon 5.5.1 and older, are affected by CVE-2018-25353.
What type of vulnerability is CVE-2018-25353?
CVE-2018-25353 is an arbitrary file upload vulnerability.
What can attackers do with CVE-2018-25353?
Attackers can exploit CVE-2018-25353 to upload executable files by bypassing file extension blacklist restrictions.