github.com
https://github.com/dahua966/Vul_disclose/blob/main/XXE_modxcms.md CVE-2020-25911
CRITICAL
XML External Entity vulnerability in MODX CMS
Record summary
CVE-2020-25911 has a selected CVSS score of 9.1 (critical).
Description
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
modx/revolutionBrowse Packagist / modx/revolution | GitHub Advisory | Before 2.8.0 · Fixed in 2.8.0 | affected |
References
6github.com
https://github.com/modxcms/revolution github.com
https://github.com/modxcms/revolution/issues/15237 github.com
https://github.com/modxcms/revolution/pull/15238 github.com
https://github.com/modxcms/revolution/pull/15238/commits/1b7ffe02df30f05dbf67dd15e4d8101687c1585a nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-25911