VDB
Sign up
MEDIUM5.4

GHSA-7hhg-xj2h-5vq9

MODX Revolution cross-site scripting vulnerability

Quick fix

GHSA-7hhg-xj2h-5vq9 — modx/revolution: upgrade to the fixed version with the command below.

composer require modx/revolution:^2.5.7

Details

In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/modx/revolution
Introduced in: 0Fixed in: 2.5.7
Fixcomposer require modx/revolution:^2.5.7

References