Описание
In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning.
Ссылки
- ExploitPatchThird Party Advisory
- PatchVendor Advisory
- ExploitPatchThird Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.5.6 (включая)
cpe:2.3:a:modx:modx_revolution:*:*:*:*:*:*:*:*
EPSS
Процентиль: 53%
0.00301
Низкий
4.7 Medium
CVSS3
2.6 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
EPSS
Процентиль: 53%
0.00301
Низкий
4.7 Medium
CVSS3
2.6 Low
CVSS2
Дефекты
CWE-79