MEDIUM6.1
GHSA-q4c2-q63g-62j7
MODX Revolution vulnerable to XSS attack through its User Photo field
Quick fix
GHSA-q4c2-q63g-62j7 — modx/revolution: upgrade to the fixed version with the command below.
composer require modx/revolution:^2.7.1-plDetails
MODX Revolution through v2.7.0-pl allows XSS via the User Photo field.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/modx/revolution
Introduced in:
0Fixed in: 2.7.1-plFix
composer require modx/revolution:^2.7.1-plReferences
- https://nvd.nist.gov/vuln/detail/CVE-2018-20755[ADVISORY]
- https://github.com/modxcms/revolution/issues/14102[WEB]
- https://github.com/modxcms/revolution/pull/14335[WEB]
- https://github.com/modxcms/revolution/commit/a12920f1698d3be8e6ba07d746da46e511b911b6[WEB]
- https://github.com/modxcms/revolution[PACKAGE]