VDB
Sign up
HIGH7.0

GHSA-cgrv-6h2h-6f7v

MODX Revolution Directory Traversal Vulnerability

Quick fix

GHSA-cgrv-6h2h-6f7v — modx/revolution: upgrade to the fixed version with the command below.

composer require modx/revolution:^2.5.7

Details

In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/modx/revolution
Introduced in: 0Fixed in: 2.5.7
Fixcomposer require modx/revolution:^2.5.7

References