MEDIUM6.1
GHSA-fpxg-5x79-43rm
MODX Revolution allows XSS via document resources
Quick fix
GHSA-fpxg-5x79-43rm — modx/revolution: upgrade to the fixed version with the command below.
composer require modx/revolution:^2.7.1-plDetails
MODX Revolution through v2.7.0-pl allows XSS via a document resource (such as pagetitle), which is mishandled during an Update action, a Quick Edit action, or the viewing of manager logs.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/modx/revolution
Introduced in:
0Fixed in: 2.7.1-plFix
composer require modx/revolution:^2.7.1-plReferences
- https://nvd.nist.gov/vuln/detail/CVE-2018-20756[ADVISORY]
- https://github.com/modxcms/revolution/issues/14105[WEB]
- https://github.com/modxcms/revolution/pull/14335[WEB]
- https://github.com/modxcms/revolution/commit/71f894ee55dc4eed10538979761d6c94e8cd1078[WEB]
- https://github.com/modxcms/revolution[PACKAGE]