github.com
https://github.com/modxcms/revolution CVE-2018-20756
MEDIUM
MODX Revolution allows XSS via document resources
Record summary
CVE-2018-20756 has a selected CVSS score of 6.1 (medium).
Description
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
modx/revolutionBrowse Packagist / modx/revolution | GitHub Advisory | Before 2.7.1-pl · Fixed in 2.7.1-pl | affected |
References
5github.com
https://github.com/modxcms/revolution/commit/71f894ee55dc4eed10538979761d6c94e8cd1078 github.com
https://github.com/modxcms/revolution/issues/14105 github.com
https://github.com/modxcms/revolution/pull/14335 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-20756