CVE-2014-8774

MODX Revolution 2.x < 2.2.15 - Cross-Site Scripting via context_key Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-8774.

AI-analyzed exploit summary This advisory details multiple vulnerabilities in MODX Revolution, including CSRF token bypass, reflected XSS via the 'context_key' parameter, and stored XSS via the 'context' parameter. It provides technical details on exploitation methods and affected URLs but does not include functional exploit code.

Description

Cross-site scripting (XSS) vulnerability in manager/index.php in MODX Revolution 2.x before 2.2.15 allows remote attackers to inject arbitrary web script or HTML via the context_key parameter.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/35159

This advisory details multiple vulnerabilities in MODX Revolution, including CSRF token bypass, reflected XSS via the 'context_key' parameter, and stored XSS via the 'context' parameter. It provides technical details on exploitation methods and affected URLs but does not include functional exploit code.

Classification
Writeup 95%
Attack Type
Xss | Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: MODX Revolution 2.0.0-2.2.14
No auth needed
Prerequisites: Victim interaction for reflected XSS · Authenticated user for stored XSS
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (2)

Core 2

Scores

EPSS 0.0146
EPSS Percentile 70.2%

Details

CWE
CWE-79
Status published
Products (29)
modx/modx_revolution 2.0.0
modx/modx_revolution 2.0.1
modx/modx_revolution 2.0.3
modx/modx_revolution 2.0.4
modx/modx_revolution 2.0.5
modx/modx_revolution 2.0.6
modx/modx_revolution 2.0.7
modx/modx_revolution 2.0.8
modx/modx_revolution 2.1.0
modx/modx_revolution 2.1.1
... and 19 more
Published Dec 03, 2014
Tracked Since Feb 18, 2026