CVE-2018-25353Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated users to bypass file extension blacklist restrictions. Attackers with editor accounts can upload executable files by using obfuscated extensions like php71 or php53 to evade the blacklist filter and execute arbitrary code.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-24: 2Technical Details · 2026-05-24: 205-24
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2018-25353 Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated users to bypass file extension blacklist restrict… https://www.cve.org/CVERecord?id=CVE-2018-25353 ----- Traducción: CVE-2018-25353 Red… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2018-25353, detailing an arbitrary file‑upload flaw in Redaxo CMS Mediapool Addon that lets authenticated users bypass file‑extension restrictions. No PoC, exploit, patch, or active exploitation is noted.

    0000024
    79 followersView on X
  • CVE@CVEnew
    General

    CVE-2018-25353 Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated users to bypass file extension blacklist restrict… https://www.cve.org/CVERecord?id=CVE-2018-25353

    Post summary

    The post describes CVE‑2018‑25353 as an arbitrary file upload flaw in Redaxo CMS Mediapool Addon that lets authenticated users bypass file type restrictions, but offers no PoC, exploit, or patch details.

    00000304
    57.5K followersView on X

Explore more