citadelo.com
https://citadelo.com/en/2017/04/modx-revolution-cms CVE-2017-9068
MEDIUM
MODX Revolution Reflected XSS
Record summary
CVE-2017-9068 has a selected CVSS score of 6.1 (medium).
Description
In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
modx/revolutionBrowse Packagist / modx/revolution | GitHub Advisory | Before 2.5.7 · Fixed in 2.5.7 | affected |
References
4github.com
https://github.com/modxcms/revolution github.com
https://github.com/modxcms/revolution/pull/13424 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-9068