Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redaxo
Redaxo core |
|
| Vendors & Products |
Redaxo
Redaxo core |
|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list.php accepts the sort request parameter without checking whether setColumnSortable() registered the requested column. An authenticated backend user can make prepareQuery() add an escaped but unauthorized ORDER BY identifier, allowing error-based enumeration of columns in joined tables and ordering by unselected sensitive fields such as rex_user.password. This issue is fixed in version 5.21.2. | |
| Title | REDAXO: Unwhitelisted ORDER BY Column in rex_list Allows Authenticated Column Enumeration | |
| Weaknesses | CWE-20 CWE-200 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-23T15:22:46.380Z
Reserved: 2026-07-14T23:10:57.032Z
Link: CVE-2026-62998
Updated: 2026-09-23T15:22:41.387Z
Status : Awaiting Analysis
Published: 2026-09-23T15:17:15.293
Modified: 2026-09-23T18:12:04.247
Link: CVE-2026-62998
No data.
OpenCVE Enrichment
Updated: 2026-09-23T16:15:05Z