CVE-2026-63000: REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates
Summary The rexapiinstallpackageupdate API function (install addon) does not override requiresCsrfProtection(), which defaults to false in the base class rexapifunction. Any authenticated admin can therefore be tricked via a CSRF attack into silently triggering a package update from the REDAXO package server.
Details File: redaxo/src/core/lib/apifunction.php:277-280 php protected function requiresCsrfProtection() { return false; // DEFAULT — subclasses must opt in }
File: redaxo/src/addons/install/lib/api/apipackageupdate.php:8-39 php class rexapiinstallpackageupdate extends rexapifunction { public function execute() { if (!rex::getUser()?->isAdmin()) { throw new rexapiexception('You do not have the permission!'); } $addonkey = rexrequest('addonkey', 'string'); $fileId = rexrequest('file', 'int'); $installer = new rexinstallpackageupdate(); // ... downloads and installs $addonkey version $fileId from redaxo.org } // requiresCsrfProtection() NOT overridden — defaults to false }
For comparison, rexapiinstallpackageadd and rexapiinstallpackagedelete both correctly return true. Only rexapiinstallpackageupdate is missing this.
PoC html <!-- Attacker-controlled page --> <img src="https://victim-redaxo.example.com/index.php?page=install/packages&rex-api-call=installpackageupdate&addonkey=someaddon&file=42" /> When an authenticated admin visits this page, the request is automatically made with their session cookie, causing someaddon to be updated to version fileid=42.
Impact An attacker who can lure an admin to a malicious page can force-install specific addon versions. If combined with a supply-chain compromise of a package on redaxo.org, or by targeting a downgrade to a known-vulnerable version, this becomes a remote code execution vector. Even without supply-chain compromise, it can be used to disrupt the site by forcing unwanted updates.
Fix Add requiresCsrfProtection() to rexapiinstallpackageupdate: php protected function requiresCsrfProtection() { return true; }
Other sources
REDAXO is a PHP-based content management system. Prior to 5.21.2, rexapiinstallpackageupdate in redaxo/src/addons/install/lib/api/apipackageupdate.php inherits the false default from rexapifunction::requiresCsrfProtection() instead of requiring a CSRF token. An unauthenticated attacker can cause a logged-in administrator's browser to request a selected package update from the configured REDAXO package server, changing installed addon code or disrupting the site without the administrator's intent. This issue is fixed in version 5.21.2.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/redaxo/sourceto a version that resolves this vulnerability.Fixed in 5.21.2 - Upgrade
Upgrade
REDAXOto a version that resolves this vulnerability.Fixed in 5.21.2
Event History
Frequently Asked Questions
Who can be targeted by this issue?
An authenticated REDAXO administrator can be targeted. The attacker must cause that administrator to interact with a CSRF payload; no attacker account or administrative permission is required.
What action can a successful attack trigger?
It can silently invoke the package-update API and cause REDAXO to download and install a selected add-on version from the REDAXO package server. The affected operation is package update, not package addition or deletion.
How can I determine whether my installation is affected?
Inspect rex_api_install_package_update in the install add-on. It is affected if the class does not override requiresCsrfProtection() to return true, because the inherited base-class default returns false.