ZeroHour

CVE-2022-26149

PoC
CVSS 3.1
7.2 high
EPSS
9%p95
Published
()
Modified
Description

MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.

Vendors
modx
Products
revolution
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.