GHSA-m8r3-22v6-g877MediumCVSS 6.4

REDAXO: Missing CSRF Protection on Package Update Action Allows Forced Addon Updates

Published
September 23, 2026
Last Modified
September 23, 2026

🔗 CVE IDs covered (1)

📋 Description

Summary

The rex_api_install_package_update API function (install addon) does not override requiresCsrfProtection(), which defaults to false in the base class rex_api_function. Any authenticated admin can therefore be tricked via a CSRF attack into silently triggering a package update from the REDAXO package server.

Details

File: redaxo/src/core/lib/api_function.php:277-280

protected function requiresCsrfProtection()
{
    return false;  // DEFAULT — subclasses must opt in
}

File: redaxo/src/addons/install/lib/api/api_package_update.php:8-39

class rex_api_install_package_update extends rex_api_function
{
    public function execute()
    {
        if (!rex::getUser()?->isAdmin()) {
            throw new rex_api_exception('You do not have the permission!');
        }
        $addonkey = rex_request('addonkey', 'string');
        $fileId = rex_request('file', 'int');
        $installer = new rex_install_package_update();
        // ... downloads and installs $addonkey version $fileId from redaxo.org
    }
    // requiresCsrfProtection() NOT overridden — defaults to false
}

For comparison, rex_api_install_package_add and rex_api_install_package_delete both correctly return true. Only rex_api_install_package_update is missing this.

PoC

<!-- Attacker-controlled page -->
<img src="https://victim-redaxo.example.com/index.php?page=install/packages&rex-api-call=install_package_update&addonkey=some_addon&file=42" />

When an authenticated admin visits this page, the request is automatically made with their session cookie, causing some_addon to be updated to version file_id=42.

Impact

An attacker who can lure an admin to a malicious page can force-install specific addon versions. If combined with a supply-chain compromise of a package on redaxo.org, or by targeting a downgrade to a known-vulnerable version, this becomes a remote code execution vector. Even without supply-chain compromise, it can be used to disrupt the site by forcing unwanted updates.

Fix

Add requiresCsrfProtection() to rex_api_install_package_update:

protected function requiresCsrfProtection()
{
    return true;
}

🎯 Affected products1

  • composer/redaxo/source:<= 5.21.1

🔗 References (5)