Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 23 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redaxo
Redaxo core |
|
| Vendors & Products |
Redaxo
Redaxo core |
|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list.php accepts the sort request parameter without checking whether setColumnSortable() registered the requested column. An authenticated backend user can make prepareQuery() add an escaped but unauthorized ORDER BY identifier, allowing error-based enumeration of columns in joined tables and ordering by unselected sensitive fields such as rex_user.password. This issue is fixed in version 5.21.2. | |
| Title | REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration | |
| Weaknesses | CWE-20 CWE-200 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-23T15:22:46.380Z
Reserved: 2026-07-14T23:10:57.032Z
Link: CVE-2026-62998
Updated: 2026-09-23T15:22:41.387Z
Status : Received
Published: 2026-09-23T15:17:15.293
Modified: 2026-09-23T16:16:43.830
Link: CVE-2026-62998
No data.
OpenCVE Enrichment
Updated: 2026-09-23T16:15:05Z