A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlier. An authenticated user with permissions to edit users can save malicious JavaScript as a User Group name and potentially take control over victims' accounts. This can lead to an escalation of privileges providing complete administrative control over the CMS.
References
Link | Resource |
---|---|
https://raw.githubusercontent.com/modxcms/revolution/v2.5.7-pl/core/docs/changelog.txt | Release Notes Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2022-10-03T16:23:10
Updated: 2022-10-03T16:23:10
Reserved: 2022-10-03T00:00:00
Link: CVE-2017-1000223
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-11-17T05:29:00.390
Modified: 2017-12-01T15:08:02.460
Link: CVE-2017-1000223
JSON object: View
Redhat Information
No data.
CWE