CVE-2018-25353

Redaxo · Mediapool Addon

The Redaxo CMS Mediapool Addon for version 5 is vulnerable to an unspecified security flaw.

Executive summary

A high-severity vulnerability in the Redaxo CMS Mediapool Addon for version 5 requires immediate remediation to prevent potential unauthorized access.

Vulnerability

This is a legacy vulnerability affecting the Mediapool Addon for Redaxo CMS. While historical, the high CVSS score indicates that it remains a serious risk if the addon is still in use on legacy systems.

Business impact

A CVSS score of 8.8 suggests that successful exploitation could lead to significant system compromise. For organizations still running older Redaxo installations, this vulnerability could result in data loss or unauthorized access to media and file management systems.

Remediation

Immediate Action: Update the Redaxo Mediapool Addon to the latest version or migrate away from unsupported versions of the CMS.

Proactive Monitoring: Review file system logs for unauthorized uploads or modifications in the media directory.

Compensating Controls: Isolate the legacy CMS environment and ensure it is not reachable from the public internet if it cannot be updated.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Legacy software often presents significant security risks. Organizations should prioritize updating or deprecating the Redaxo Mediapool Addon to eliminate this high-severity vulnerability from their infrastructure.