Reflected cross-site scripting (XSS) In modx/revolution
Description
MODX Revolution Reflected XSS In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
packagist | 2.5.7 |
Aliases
1. 2. 3. 4.
References
1. 2.