A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote users to inject arbitrary web script or HTML via the Output code field in modules. The payload is executed when a user views or edits an article by adding slice that uses the compromised module.
References
| Link | Resource |
|---|---|
| https://drive.google.com/drive/folders/1SpwL548ZBRYU_uL8W7Riv7VHshr2UN0R?usp=sharing | Exploit |
| https://github.com/redaxo/redaxo | Product |
| https://github.com/vettrivel007/CVE-Disclosures/blob/main/CVE-2025-64049.md | Exploit Mitigation Third Party Advisory |
Configurations
History
03 Dec 2025, 17:06
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://drive.google.com/drive/folders/1SpwL548ZBRYU_uL8W7Riv7VHshr2UN0R?usp=sharing - Exploit | |
| References | () https://github.com/redaxo/redaxo - Product | |
| References | () https://github.com/vettrivel007/CVE-Disclosures/blob/main/CVE-2025-64049.md - Exploit, Mitigation, Third Party Advisory | |
| First Time |
Redaxo
Redaxo redaxo |
|
| CPE | cpe:2.3:a:redaxo:redaxo:5.20.0:*:*:*:*:*:*:* |
25 Nov 2025, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-25 16:16
Updated : 2025-12-03 17:06
NVD link : CVE-2025-64049
Mitre link : CVE-2025-64049
CVE.ORG link : CVE-2025-64049
JSON object : View
Products Affected
redaxo
- redaxo
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
