github.com
https://github.com/modxcms/revolution CVE-2018-20757
MEDIUM
MODX Revolution allows XSS through extended user fields
Record summary
CVE-2018-20757 has a selected CVSS score of 6.1 (medium).
Description
MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
modx/revolutionBrowse Packagist / modx/revolution | GitHub Advisory | Before 2.7.1-pl · Fixed in 2.7.1-pl | affected |
References
4github.com
https://github.com/modxcms/revolution/commit/489b13c61673ea0b19124e18cf1f3e7673f8aa64 github.com
https://github.com/modxcms/revolution/issues/14104 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-20757