VDB
Sign up
MEDIUM5.4

GHSA-hm54-fg2w-2g6j

MODX allows cross-site scripting (XSS) via an SVG file

Details

A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/modx/revolution
Introduced in: 0

No fixed version published yet for modx/revolution (composer). Pin to a known-safe version or switch to an alternative.

References