PT-2022-8020 · Modx · Sterc Google Analytics Dashboard For Modx

Published

2022-12-30

·

Updated

2024-05-17

·

CVE-2017-20155

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Sterc Google Analytics Dashboard for MODX versions up to 1.0.5
Description A vulnerability was found in the Sterc Google Analytics Dashboard for MODX, affecting an unknown functionality of the file core/components/analyticsdashboardwidget/elements/tpl/widget.analytics.tpl of the component Internal Search. The manipulation leads to cross site scripting. The attack can be launched remotely.
Recommendations For Sterc Google Analytics Dashboard for MODX versions up to 1.0.5, upgrade to version 1.0.6 to address this issue. As a temporary workaround, consider restricting access to the vulnerable file core/components/analyticsdashboardwidget/elements/tpl/widget.analytics.tpl until the upgrade is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2017-20155

Affected Products

Sterc Google Analytics Dashboard For Modx