PT-2019-11497 · Modx · Modx Revolution
Published
2019-07-24
·
Updated
2020-09-30
·
CVE-2019-1010178
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Fred MODX Revolution versions prior to 1.0.0-beta5
Description:
The issue is related to incorrect access control, allowing remote code execution. This can be achieved by uploading a PHP file or modifying data in the database. The vulnerable component is assets/components/fred/web/elfinder/connector.php.
Recommendations:
For versions prior to 1.0.0-beta5, apply the fixes from the commits https://github.com/modxcms/fred/commit/139cefac83b2ead90da23187d92739dec79d3ccd and https://github.com/modxcms/fred/commit/01f0a3d1ae7f3970639c2a0db1887beba0065246 to resolve the issue. As a temporary workaround, consider restricting access to the connector.php file in the elFinder component to minimize the risk of exploitation.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Modx Revolution