PT-2019-11497 · Modx · Modx Revolution

Published

2019-07-24

·

Updated

2020-09-30

·

CVE-2019-1010178

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Fred MODX Revolution versions prior to 1.0.0-beta5
Description: The issue is related to incorrect access control, allowing remote code execution. This can be achieved by uploading a PHP file or modifying data in the database. The vulnerable component is assets/components/fred/web/elfinder/connector.php.
Recommendations: For versions prior to 1.0.0-beta5, apply the fixes from the commits https://github.com/modxcms/fred/commit/139cefac83b2ead90da23187d92739dec79d3ccd and https://github.com/modxcms/fred/commit/01f0a3d1ae7f3970639c2a0db1887beba0065246 to resolve the issue. As a temporary workaround, consider restricting access to the connector.php file in the elFinder component to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-1010178

Affected Products

Modx Revolution