VDB
Sign up
MEDIUM4.7

GHSA-p2j4-vrgx-96qg

MODX Revolution XSS via HTTP Host header

Quick fix

GHSA-p2j4-vrgx-96qg — modx/revolution: upgrade to the fixed version with the command below.

composer require modx/revolution:^2.5.7

Details

In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/modx/revolution
Introduced in: 0Fixed in: 2.5.7
Fixcomposer require modx/revolution:^2.5.7

References