Record summary

CVE-2018-20756 has a selected CVSS score of 6.1 (medium).

Description

MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.

Description source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
GitHub AdvisoryBefore 2.7.1-pl · Fixed in 2.7.1-plaffected

References

5