Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Alroniks

#18394de 53,633
14.7CVSS total
Vulnerabilidades · 2
Alta
2
PT-2018-9375
7.2
2018-07-13
Modx · Modx Revolution · CVE-2018-1000207
**Name of the Vulnerable Software and Affected Versions** MODX Revolution versions prior to 2.6.5 **Description** The issue is related to incorrect access control in filtering user parameters before passing them into the phpthumb class, which can result in creating a file with a custom filename and content. This can be exploited via a web request. **Recommendations** For MODX Revolution versions prior to 2.6.5, update to version 2.6.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the phpthumb class until a patch is available.
PT-2018-9376
7.5
2018-07-13
Modx · Modx Revolution · CVE-2018-1000208
**Name of the Vulnerable Software and Affected Versions** MODX Revolution versions prior to 2.6.5 **Description** The issue is related to a Directory Traversal vulnerability in the /core/model/modx/modmanagerrequest.class.php file. This can be exploited via a web request to the security/login processor, potentially allowing the removal of files. The vulnerability was fixed in pull 13980. **Recommendations** For MODX Revolution versions prior to 2.6.5, update to version 2.6.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the security/login processor to minimize the risk of exploitation.