Описание
MODX Revolution cross-site scripting vulnerability
In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.
Пакеты
Наименование
modx/revolution
composer
Затронутые версииВерсия исправления
< 2.5.7
2.5.7
Связанные уязвимости
CVSS3: 5.4
nvd
больше 8 лет назад
In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.