Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Agelxnash

#20704de 53,635
12.2CVSS total
Vulnerabilidades · 2
Média
2
PT-2019-10204
6.1
2019-02-06
Modx · Modx Revolution · CVE-2018-20756
Name of the Vulnerable Software and Affected Versions: MODX Revolution versions prior to v2.8.0, specifically versions through v2.7.0-pl Description: The issue allows for XSS attacks via a document resource, such as `pagetitle`, which is mishandled during certain actions like Update, Quick Edit, or when viewing manager logs. Recommendations: For MODX Revolution versions through v2.7.0-pl, update to a version later than v2.7.0-pl to resolve the issue.
PT-2019-10205
6.1
2019-02-06
Modx · Modx Revolution · CVE-2018-20757
Name of the Vulnerable Software and Affected Versions: MODX Revolution versions prior to v2.7.0-pl Description: The issue allows for XSS attacks via an extended user field, such as Container name or Attribute name. Recommendations: For MODX Revolution versions prior to v2.7.0-pl, update to a version that contains a fix for this issue.