Vulnerability Description
REDAXO is a PHP-based CMS. In Redaxo before 5.18.3, the mediapool/media page is vulnerable to arbitrary file upload. This vulnerability is fixed in 5.18.3.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redaxo | Redaxo | < 5.18.3 |
Related Weaknesses (CWE)
References
- https://github.com/redaxo/redaxo/commit/3b2159bb45da0ab6cfaef5c8cf8b602ee5e2fb37Patch
- https://github.com/redaxo/redaxo/security/advisories/GHSA-wppf-gqj5-fc4fExploitVendor Advisory
FAQ
What is CVE-2025-27411?
CVE-2025-27411 is a vulnerability with a CVSS score of 5.4 (MEDIUM). REDAXO is a PHP-based CMS. In Redaxo before 5.18.3, the mediapool/media page is vulnerable to arbitrary file upload. This vulnerability is fixed in 5.18.3.
How severe is CVE-2025-27411?
CVE-2025-27411 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-27411?
Check the references section above for vendor advisories and patch information. Affected products include: Redaxo Redaxo.