CVE-2014-2736
MODX Revolution < 2.2.14 - SQL Injection via Session ID or User/ID Parameters
Title source: llmDescription
Multiple SQL injection vulnerabilities in MODX Revolution before 2.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) session ID (PHPSESSID) to index.php or remote authenticated users to execute arbitrary SQL commands via the (2) user parameter to connectors/security/message.php or (3) id parameter to manager/index.php.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/66990
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/58036
Third Party Advisory mailing-list
x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2014-04/0124.html
Vendor Advisory x_refsource_confirm
http://forums.modx.com/thread/90173/modx-revolution-2-2-13-and-prior-blind-sql-injection
Scores
EPSS
0.0126
EPSS Percentile
66.5%
Details
CWE
CWE-89
Status
published
Products (28)
modx/modx_revolution
2.0.0
modx/modx_revolution
2.0.1
modx/modx_revolution
2.0.3
modx/modx_revolution
2.0.4
modx/modx_revolution
2.0.5
modx/modx_revolution
2.0.6
modx/modx_revolution
2.0.7
modx/modx_revolution
2.0.8
modx/modx_revolution
2.1.0
modx/modx_revolution
2.1.1
... and 18 more
Published
Apr 24, 2014
Tracked Since
Feb 18, 2026