CVE-2017-9068 Information
Feb 14, 2021
cve
Description
In MODX Revolution before 2.5.7 an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page as demonstrated by the database_type parameter.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://citadelo.com/en/2017/04/modx-revolution-cms/ https://github.com/modxcms/revolution/pull/13424
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: