VulnerabilityModified
CVE-2017-9068
In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.
MEDIUM 6.1EPSS 0.69%
Does this matter?
Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.
Description
In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- modx/modx revolution
- Source
- cve@mitre.org
References
- https://citadelo.com/en/2017/04/modx-revolution-cms/Exploit, Patch, Third Party Advisory
- https://github.com/modxcms/revolution/pull/13424
- https://citadelo.com/en/2017/04/modx-revolution-cms/Exploit, Patch, Third Party Advisory
- https://github.com/modxcms/revolution/pull/13424
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.