Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Agelxnash

#20704of 53,633
12.2Total CVSS
Vulnerabilities · 2
Medium
2
PT-2019-10204
6.1
2019-02-06
Modx · Modx Revolution · CVE-2018-20756
Name of the Vulnerable Software and Affected Versions: MODX Revolution versions prior to v2.8.0, specifically versions through v2.7.0-pl Description: The issue allows for XSS attacks via a document resource, such as `pagetitle`, which is mishandled during certain actions like Update, Quick Edit, or when viewing manager logs. Recommendations: For MODX Revolution versions through v2.7.0-pl, update to a version later than v2.7.0-pl to resolve the issue.
PT-2019-10205
6.1
2019-02-06
Modx · Modx Revolution · CVE-2018-20757
Name of the Vulnerable Software and Affected Versions: MODX Revolution versions prior to v2.7.0-pl Description: The issue allows for XSS attacks via an extended user field, such as Container name or Attribute name. Recommendations: For MODX Revolution versions prior to v2.7.0-pl, update to a version that contains a fix for this issue.