CVE-2018-25353
Redaxo · Mediapool Addon
The Redaxo CMS Mediapool Addon for version 5 is vulnerable to an unspecified security flaw.
Executive summary
A high-severity vulnerability in the Redaxo CMS Mediapool Addon for version 5 requires immediate remediation to prevent potential unauthorized access.
Vulnerability
This is a legacy vulnerability affecting the Mediapool Addon for Redaxo CMS. While historical, the high CVSS score indicates that it remains a serious risk if the addon is still in use on legacy systems.
Business impact
A CVSS score of 8.8 suggests that successful exploitation could lead to significant system compromise. For organizations still running older Redaxo installations, this vulnerability could result in data loss or unauthorized access to media and file management systems.
Remediation
Immediate Action: Update the Redaxo Mediapool Addon to the latest version or migrate away from unsupported versions of the CMS.
Proactive Monitoring: Review file system logs for unauthorized uploads or modifications in the media directory.
Compensating Controls: Isolate the legacy CMS environment and ensure it is not reachable from the public internet if it cannot be updated.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Legacy software often presents significant security risks. Organizations should prioritize updating or deprecating the Redaxo Mediapool Addon to eliminate this high-severity vulnerability from their infrastructure.