Логотип exploitDog
bind:CVE-2025-28010
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-28010

Количество 2

Количество 2

nvd логотип

CVE-2025-28010

11 месяцев назад

A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-hm54-fg2w-2g6j

11 месяцев назад

MODX allows cross-site scripting (XSS) via an SVG file

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-28010

A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.

CVSS3: 5.4
0%
Низкий
11 месяцев назад
github логотип
GHSA-hm54-fg2w-2g6j

MODX allows cross-site scripting (XSS) via an SVG file

CVSS3: 5.4
0%
Низкий
11 месяцев назад

Уязвимостей на страницу