VDB
Sign up
MEDIUM6.1

GHSA-vrw6-7vgj-vj7x

MODX Revolution Reflected XSS

Quick fix

GHSA-vrw6-7vgj-vj7x — modx/revolution: upgrade to the fixed version with the command below.

composer require modx/revolution:^2.5.7

Details

In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/modx/revolution
Introduced in: 0Fixed in: 2.5.7
Fixcomposer require modx/revolution:^2.5.7

References