CVE-2017-9067
In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.82%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.
- CVSS 3.0
- 7.0 HIGHCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.82% probability · 55th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- modx/modx revolution · php/php
- Source
- cve@mitre.org
References
- https://citadelo.com/en/2017/04/modx-revolution-cms/Exploit, Third Party Advisory
- https://github.com/modxcms/revolution/pull/13422Third Party Advisory
- https://github.com/modxcms/revolution/pull/13428Third Party Advisory
- https://citadelo.com/en/2017/04/modx-revolution-cms/Exploit, Third Party Advisory
- https://github.com/modxcms/revolution/pull/13422Third Party Advisory
- https://github.com/modxcms/revolution/pull/13428Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.