Record summary

CVE-2017-9070 has a selected CVSS score of 5.4 (medium).

Description

In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 2.5.7 · Fixed in 2.5.7affected

References

4