<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 14:37:41 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-343505</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343505</link>
      <description>EUVD-2026-343505</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343505</guid>
    </item>
    <item>
      <title>fkie_cve-2026-53599</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-53599</link>
      <description>&lt;p&gt;REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polyglot named shell.php.any.jpg, which web servers with multi-extension PHP handlers can execute as the web-server user. This issue is fixed in version 5.21.1.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;REDAXO is a PHP-based content management system. From 5.18.2 until 5.21.1, rex_mediapool::isAllowedExtension in redaxo/src/addons/mediapool/lib/mediapool.php lets an authenticated backend user with media[upload] permission upload a JPEG/PHP polyglot named shell.php.any.jpg, which web servers with multi-extension PHP handlers can execute as the web-server user. This issue is fixed in version 5.21.1.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-53599</guid>
    </item>
    <item>
      <title>GHSA-98pp-vccm-qm25 — Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache m…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-98pp-vccm-qm25</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: redaxo/source&lt;/p&gt;
&lt;p&gt;## Summary
 
`rex_mediapool::isAllowedExtension` in `redaxo/src/addons/mediapool/lib/mediapool.php` accepts filenames that contain a blocked extension as a non-terminal segment of a longer extension chain, for example `shell.php.any.jpg`. The check only catches the blocked extension when it appears at the end of the filename or immediately before the final extension. An authenticated backend user with mediapool upload permission can upload a JPEG/PHP polyglot named `shell.php.any.jpg` and, on web servers whose PHP handler matches `.php` as any segment (mod_mime `AddHandler`-style, or any `FilesMatch` regex without an end anchor), request the file from the public `media/` directory to execute arbitrary PHP as the web-server user.
 
The vulnerable check is a **regression** introduced in commit [`9d008697d`](https://github.com/redaxo/core/commit/9d008697dcec6bf5a972bdc081fadb68e9dab7fa) (PR #6213, Feb 7 2025), which weakened a previously correct `str_contains` check into a pair of `str_ends_with` checks. The earlier check, in place since 2018 specifically to defend against double-extension attacks, would have blocked this payload.
 
The regression has shipped in every release from 5.18.2 through 5.21.0.&lt;/p&gt;
&lt;p&gt;## Details
## Root cause
 
At the audited commit `6e0de42`, `isAllowedExtension` performs three checks against the blocked-extension list:
 
```php
// redaxo/src/addons/mediapool/lib/mediapool.php (104–130) @ 6e0de42
public static function isAllowedExtension(string $filename, a…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: redaxo/source&lt;/p&gt;
&lt;p&gt;## Summary
 
`rex_mediapool::isAllowedExtension` in `redaxo/src/addons/mediapool/lib/mediapool.php` accepts filenames that contain a blocked extension as a non-terminal segment of a longer extension chain, for example `shell.php.any.jpg`. The check only catches the blocked extension when it appears at the end of the filename or immediately before the final extension. An authenticated backend user with mediapool upload permission can upload a JPEG/PHP polyglot named `shell.php.any.jpg` and, on web servers whose PHP handler matches `.php` as any segment (mod_mime `AddHandler`-style, or any `FilesMatch` regex without an end anchor), request the file from the public `media/` directory to execute arbitrary PHP as the web-server user.
 
The vulnerable check is a **regression** introduced in commit [`9d008697d`](https://github.com/redaxo/core/commit/9d008697dcec6bf5a972bdc081fadb68e9dab7fa) (PR #6213, Feb 7 2025), which weakened a previously correct `str_contains` check into a pair of `str_ends_with` checks. The earlier check, in place since 2018 specifically to defend against double-extension attacks, would have blocked this payload.
 
The regression has shipped in every release from 5.18.2 through 5.21.0.&lt;/p&gt;
&lt;p&gt;## Details
## Root cause
 
At the audited commit `6e0de42`, `isAllowedExtension` performs three checks against the blocked-extension list:
 
```php
// redaxo/src/addons/mediapool/lib/mediapool.php (104–130) @ 6e0de42
public static function isAllowedExtension(string $filename, a…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-98pp-vccm-qm25</guid>
    </item>
  </channel>
</rss>
