Record summary

CVE-2017-9071 has a selected CVSS score of 4.7 (medium).

Description

In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 2.5.7 · Fixed in 2.5.7affected

References

4