Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

GHSA-4f5f-j737-pm58

MediumCVSS 4.3 / 10
Published Sep 24, 2026·Last modified Sep 24, 2026
Affected Components(1)
Packagist logoredaxo/source
< 5.21.2
Description

Summary

The rex_list component reads the SQL sort column directly from the sort GET parameter without validating it against the set of columns declared sortable via setColumnSortable(). Although the value is wrapped in backticks via escapeIdentifier() (preventing classical SQL injection), this still allows any authenticated backend user to ORDER BY any column in the query's FROM tables, including unselected sensitive columns such as password from the rex_user table, and perform error-based column enumeration.

Details

File: redaxo/src/core/lib/list.php:976-982 — getSortColumn() returns the raw request parameter without whitelist check:

public function getSortColumn($default = null)
{
    if (rex_request('list', 'string') == $this->getName()) {
        return rex_request('sort', 'string', $default);  // NO validation against sortable columns
    }
    return $default;
}

File: redaxo/src/core/lib/list.php:899-911 — prepareQuery() uses it directly in the ORDER BY clause:

protected function prepareQuery($query, array $defaultSort = [])
{
    $sortColumn = $this->getSortColumn();
    if ('' != $sortColumn) {
        $sql = rex_sql::factory($this->db);
        $sortColumn = $sql->escapeIdentifier($sortColumn);  // backtick-wraps, but no whitelist
        if ($defaultSort || false === stripos($query, ' ORDER BY ')) {
            $query .= ' ORDER BY ' . $sortColumn . ' ' . $sortType;
        }
    }

The users list queries rex_user which contains password, previous_passwords, password_change_required — not in the SELECT. Specifying a non-existent column name produces a MySQL Unknown column exception whose message is propagated to the user, confirming or denying column existence.

PoC

Column enumeration (error-based):

GET /redaxo/index.php?page=users&list=<list_name>&sort=nonexistent_col&sorttype=asc

Response will contain: Unknown column 'nonexistent_col' in 'order clause'

Sort by password hash (data ordering leak):

GET /redaxo/index.php?page=users&list=<list_name>&sort=password&sorttype=asc

Users are silently reordered by their Argon2 password hash.

Impact

Authenticated backend users (non-admin) can enumerate database column names of internal tables via error messages and manipulate query ordering to include sensitive unselected columns. While this does not allow arbitrary SQL execution due to backtick escaping, it constitutes an information disclosure vulnerability enabling targeted further attacks.

Fix

Validate the sort request parameter against the whitelist of columns registered with setColumnSortable() before use in the query:

public function getSortColumn($default = null)
{
    if (rex_request('list', 'string') == $this->getName()) {
        $requested = rex_request('sort', 'string', $default);
        if ($requested !== null && $this->hasColumnOption($requested, REX_LIST_OPT_SORT)) {
            return $requested;
        }
    }
    return $default;
}
Upload your SBOM

Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.

Risk Scores
Base Score
4.3

The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker needs basic access or low-level privileges. No user interaction is needed for the attacker to exploit this vulnerability. The impact is confined to the system where the vulnerability exists. There is a low impact on the confidentiality of the information.

Threat Intelligence
4.0

Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.

EPSS
0.27%

The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Browse More

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard