ZeroHour

CVE-2017-9068

PoC
CVSS 3.0
6.1 medium
EPSS
<1%p51
Published
()
Modified
Description

In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.

Vendors
modx
Products
modx revolution
Weakness
CWE-79
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.