CVE-2014-2736

MODX Revolution < 2.2.14 - SQL Injection via Session ID or User/ID Parameters

Title source: llm
STIX 2.1

Description

Multiple SQL injection vulnerabilities in MODX Revolution before 2.2.14 allow remote attackers to execute arbitrary SQL commands via the (1) session ID (PHPSESSID) to index.php or remote authenticated users to execute arbitrary SQL commands via the (2) user parameter to connectors/security/message.php or (3) id parameter to manager/index.php.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/66990
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58036
Third Party Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2014-04/0124.html

Scores

EPSS 0.0126
EPSS Percentile 66.5%

Details

CWE
CWE-89
Status published
Products (28)
modx/modx_revolution 2.0.0
modx/modx_revolution 2.0.1
modx/modx_revolution 2.0.3
modx/modx_revolution 2.0.4
modx/modx_revolution 2.0.5
modx/modx_revolution 2.0.6
modx/modx_revolution 2.0.7
modx/modx_revolution 2.0.8
modx/modx_revolution 2.1.0
modx/modx_revolution 2.1.1
... and 18 more
Published Apr 24, 2014
Tracked Since Feb 18, 2026