MEDIUM6.1
GHSA-vrw6-7vgj-vj7x
MODX Revolution Reflected XSS
Quick fix
GHSA-vrw6-7vgj-vj7x — modx/revolution: upgrade to the fixed version with the command below.
composer require modx/revolution:^2.5.7Details
In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.
Are you affected?
Enter the version of the package you're using.