Record summary

CVE-2017-9068 has a selected CVSS score of 6.1 (medium).

Description

In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 2.5.7 · Fixed in 2.5.7affected

References

4