MEDIUM5.4
GHSA-vwqw-wfhv-2xcq
MODX vulnerability allows for XSS via user settings parameters
Quick fix
GHSA-vwqw-wfhv-2xcq — modx/revolution: upgrade to the fixed version with the command below.
composer require modx/revolution:^2.7.1-plDetails
MODX Revolution through v2.7.0-pl allows XSS via User Settings such as Description.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/modx/revolution
Introduced in:
0Fixed in: 2.7.1-plFix
composer require modx/revolution:^2.7.1-pl