CVE-2026-62998: REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration

Published Sep 23, 2026
·
Updated

REDAXO is a PHP-based content management system. Prior to 5.21.2, rexlist::getSortColumn() in redaxo/src/core/lib/list.php accepts the sort request parameter without checking whether setColumnSortable() registered the requested column. An authenticated backend user can make prepareQuery() add an escaped but unauthorized ORDER BY identifier, allowing error-based enumeration of columns in joined tables and ordering by unselected sensitive fields such as rexuser.password. This issue is fixed in version 5.21.2.

Affected Software

1 affected component
REDAXO REDAXO<5.21.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade REDAXO to a version that resolves this vulnerability.

    Fixed in 5.21.2

Event History

Sep 23, 2026
CVE Published
via MITRE·02:07 PM
Data Sourced
via MITRE·02:07 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated REDAXO backend user can exploit it. No user interaction is required, and the attack can be performed over the network.

2

Which deployments are affected?

REDAXO versions prior to 5.21.2 are affected where rex_list::getSortColumn() processes the sort request parameter. Version 5.21.2 contains the fix.

3

What can an attacker obtain or do?

An attacker can use error-based behavior to enumerate columns in joined tables and can order results using unselected sensitive fields, including rex_user.password. The provided severity vector indicates low confidentiality impact, with no integrity or availability impact.

4

How can I mitigate the issue if I cannot upgrade immediately?

The provided data does not identify a workaround. Restricting access to authenticated backend accounts can reduce exposure because exploitation requires a backend user account.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203